openSUSE-SU-2020:1433-1

    Dashboard / Vulnerabilities / openSUSE-SU-2020:1433-1

    openSUSE-SU-2020:1433-1

    Published: 14 Sept 2020Last Modified: 4 Feb 2026
    Upstream:

    Summary: Security update for docker-distribution

    Details: This update for docker-distribution fixes the following issues: - Enable build on %arm (which include armv6), not only on armv7 - Enable ppc64le - Use correct URL to project - Remove fillup, we don't ship a sysconfig file - Correct systemd requires - Enable build on ARM - Upgraded to 2.7.1 - Support for OCI images added - Fix upgrade issues from 2.6.x - Update Go version to 1.11 - Switch to multi-stage Dockerfile - Validations enabled by default with new disabled config option - Optimize health check performance - Create separate permission for deleting objects in a repo - Fix storage driver error propagation for manifest GETs - Fix forwarded header resolution - Add prometheus metrics - Disable schema1 manifest by default - Graceful shutdown - TLS: remove ciphers that do not support perfect forward secrecy - Fix registry stripping newlines from manifests - Add bugsnag logrus hook - Support ARM builds This release is a special security release to address an issue allowing an attacker to force arbitrarily-sized memory allocations in a registry instance through the manifest endpoint. The problem has been mitigated by limiting the size of reads for image manifest content. Details for mitigation are in 29fa466 Fixes boo#1049850 (CVE-2017-11468) Fixes boo#1033172

    Affected packages

    Package

    Name: docker-distribution

    Purl: pkg:rpm/suse/docker-distribution&distro=SUSE%20Package%20Hub%2015%20SP2

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.7.1-bp152.4.3.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    openSUSE-SU-2020:1433-1 | CVE-DB