First published: Wed Nov 17 2021(Updated: )
In the OCI Distribution Specification version 1.0.0 and prior and in the OCI Image Specification version 1.0.1 and prior, manifest and index documents are ambiguous without an accompanying Content-Type HTTP header. Versions of Moby (Docker Engine) prior to 20.10.11 treat the Content-Type header as trusted and deserialize the document according to that header. If the Content-Type header changed between pulls of the same ambiguous document (with the same digest), the document may be interpreted differently, meaning that the digest alone is insufficient to unambiguously identify the content of the image. References: <a href="https://github.com/moby/moby/security/advisories/GHSA-xmmx-7jpf-fx42">https://github.com/moby/moby/security/advisories/GHSA-xmmx-7jpf-fx42</a> <a href="https://github.com/opencontainers/distribution-spec/security/advisories/GHSA-mc8v-mgrf-8f4m">https://github.com/opencontainers/distribution-spec/security/advisories/GHSA-mc8v-mgrf-8f4m</a> <a href="https://github.com/opencontainers/image-spec/security/advisories/GHSA-77vh-xpmg-72qh">https://github.com/opencontainers/image-spec/security/advisories/GHSA-77vh-xpmg-72qh</a> <a href="https://github.com/containerd/containerd/releases/tag/v1.4.12">https://github.com/containerd/containerd/releases/tag/v1.4.12</a> <a href="https://github.com/containerd/containerd/releases/tag/v1.5.8">https://github.com/containerd/containerd/releases/tag/v1.5.8</a> <a href="https://github.com/moby/moby/releases/tag/v20.10.11">https://github.com/moby/moby/releases/tag/v20.10.11</a> <a href="https://github.com/containerd/containerd/security/advisories/GHSA-5j5w-g665-5m35">https://github.com/containerd/containerd/security/advisories/GHSA-5j5w-g665-5m35</a>
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/cri-o | <0:1.23.0-92.rhaos4.10.gitdaab4d1.el7 | 0:1.23.0-92.rhaos4.10.gitdaab4d1.el7 |
redhat/opencontainers/image-spec | <1.0.1 | 1.0.1 |
LinuxFoundation Open Container Initiative Distribution Specification | <=1.0.0 | |
Linux Foundation Open Container Initiative Image Format Specification | <=1.0.1 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 |
https://github.com/opencontainers/distribution-spec/commit/ac28cac0557bcd3084714ab09f9f2356fe504923
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2021-41190 has a medium severity rating due to the ambiguity in manifest and index documents.
To fix CVE-2021-41190, upgrade to cri-o version 0:1.23.0-92.rhaos4.10.gitdaab4d1.el7 or opencontainers/image-spec version 1.0.1.
CVE-2021-41190 affects OCI Distribution Specification versions 1.0.0 and prior, and OCI Image Specification versions 1.0.1 and prior.
The vulnerable software includes cri-o versions prior to 0:1.23.0 and opencontainers/image-spec versions prior to 1.0.1.
CVE-2021-41190 affects various Linux distributions, including specific versions of Fedora.