Alerts This Week
Warning Icon 1 905
Alerts This Week
Warning Icon 1 905

openSUSE Leap 15.6 advisory: 2025:02282-1 moderate: umoci security issue

opensuse
Calendar Grey July 11, 2025
Dist Opensuse Esm H88
Significant security revision disclosed for umoci in openSUSE tackling CVE-2021-41190 along with patch guidance.
An update that solves one vulnerability can now be installed.

Description

This update for umoci fixes the following issues:

Update to umoci v0.5.0. Upstream changelog is available from

bsc#1243388

A security flaw was found in the OCI image-spec, where it is possible to cause a

blob with one media-type to be interpreted as a different media-type. As umoci

is not a registry nor does it handle signatures, this vulnerability had no real

impact on umoci but for safety we implemented the now-recommended media-type

embedding and verification. CVE-2021-41190

Other changes in this release:

* Several large reworks and API-related changes to the umoci's overlayfs

support. This is only available to Go API users.

* The runtime-spec config.json generated by umoci is updated to be more modern

and work properly with modern runc versions.

* The default gzip compression blocksize has been adjusted to match Docker.

* zstd-compressed images are now fully supported. Users can explcitily request

the compression algorithm for newly-generated layers with...

Read the Full Advisory

Patch

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server 15 SP5 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2025-2282=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP3

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP3-2025-2282=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2025-2282=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP5

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2025-2282=1

* SUSE Manager Proxy 4.3

zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Proxy-4.3-2025-2282=1

* SUSE Manager Retail Branch Server 4.3

zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Retail-Branch-

Server-4.3-2025-2282=1

* SUSE Manager Server 4.3

zypper in -t patch SUSE-SLE-Product-SUSE-Manager-Server-4.3-2025-2282=1

* SUSE Enterprise...

Read the Full Advisory

Package List

* SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64)

* umoci-0.5.0-150000.3.15.1

* SUSE Linux Enterprise Server for SAP Applications 15 SP3 (ppc64le x86_64)

* umoci-0.5.0-150000.3.15.1

* SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64)

* umoci-0.5.0-150000.3.15.1

* SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64)

* umoci-0.5.0-150000.3.15.1

* SUSE Manager Proxy 4.3 (x86_64)

* umoci-0.5.0-150000.3.15.1

* SUSE Manager Retail Branch Server 4.3 (x86_64)

* umoci-0.5.0-150000.3.15.1

* SUSE Manager Server 4.3 (ppc64le s390x x86_64)

* umoci-0.5.0-150000.3.15.1

* SUSE Enterprise Storage 7.1 (aarch64 x86_64)

* umoci-0.5.0-150000.3.15.1

* openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64)

* umoci-0.5.0-150000.3.15.1

* Basesystem Module 15-SP6 (aarch64 ppc64le s390x x86_64)

* umoci-0.5.0-150000.3.15.1

* Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64)

* umoci-0.5.0-150000.3.15.1

* SUSE Linux Enterprise High Performance Computing LTSS 15 SP3...

Read the Full Advisory

References

* bsc#1243388

## References:

* https://www.suse.com/security/cve/CVE-2021-41190.html

* https://bugzilla.suse.com/show_bug.cgi?id=1243388

Announcement ID: SUSE-SU-2025:02282-1
Release Date: 2025-07-11T08:35:10Z
Affected Products: * Basesystem Module 15-SP6 * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP3 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 LTSS * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here