shield Security update for umoci
SUSE-SLE-Module-Basesystem-15-SP7-2025-2282


This update for umoci fixes the following issues: Update to umoci v0.5.0. Upstream changelog is available from <https://github.com/opencontainers/umoci/releases/tag/v0.5.0> bsc#1243388 A security flaw was found in the OCI image-spec, where it is possible to cause a blob with one media-type to be interpreted as a different media-type. As umoci is not a registry nor does it handle signatures, this vulnerability had no real impact on umoci but for safety we implemented the now-recommended media-type embedding and verification. CVE-2021-41190 Other changes in this release: * Several large reworks and API-related changes to the umoci's overlayfs support. This is only available to Go API users. * The runtime-spec config.json generated by umoci is updated to be more modern and work properly with modern runc versions. * The default gzip compression blocksize has been adjusted to match Docker. * zstd-compressed images are now fully supported. Users can explcitily request the compression algorithm for newly-generated layers with the --compress option.

  • Release Date
    Jul 11 2025
  • References
    Bugzilla: 1243388
    CVEs: CVE-2021-41190
  • Type
    security
  • Severity
    moderate

cloud_download Downloads

Basesystem Module 15.7 x86_64
  • Packages
    umoci
    Open Container Image manipulation tool
    0.5.0-150000.3.15.1 lock rpm lock src
Basesystem Module 15.7 ppc64le
  • Packages
    umoci
    Open Container Image manipulation tool
    0.5.0-150000.3.15.1 lock rpm lock src
Basesystem Module 15.7 aarch64
  • Packages
    umoci
    Open Container Image manipulation tool
    0.5.0-150000.3.15.1 lock rpm lock src
Basesystem Module 15.7 s390x
  • Packages
    umoci
    Open Container Image manipulation tool
    0.5.0-150000.3.15.1 lock rpm lock src