PT-2021-7848 · Unknown+7 · Oci Distribution Specification+7

Jonjohnsonjr

·

Published

2021-11-17

·

Updated

2025-10-11

·

CVE-2021-41190

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OCI Distribution Specification versions 1.0.0 and prior
Description The issue concerns the OCI Distribution Specification, which defines an API protocol for content distribution. In versions 1.0.0 and prior, the Content-Type header alone was used to determine the document type during push and pull operations. This could lead to ambiguous interpretations of documents containing both manifests and layers fields or manifests and config fields, especially if the Content-Type header changed between pulls of the same digest. The specification has been updated to require matching mediaType values and Content-Type headers. Clients may distrust the Content-Type header and reject ambiguous documents if they cannot update to version 1.0.1.
Recommendations For OCI Distribution Specification versions 1.0.0 and prior, update to version 1.0.1 to ensure that mediaType values match the Content-Type header used during push and pull operations. As a temporary workaround, consider having clients distrust the Content-Type header and reject ambiguous documents that contain both manifests and layers fields or manifests and config fields until the update to version 1.0.1 is possible.

Fix

Type Confusion

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3437
ALT-PU-2021-3495
ALT-PU-2021-3539
ALT-PU-2021-3549
ALT-PU-2022-1248
ALT-PU-2022-1252
AZL-44865
AZL-44925
BDU:2023-03675
CESA-2022_7457
CVE-2021-41190
GHSA-MC8V-MGRF-8F4M
GO-2024-2914
MGASA-2021-0531
MGASA-2022-0006
MGASA-2023-0213
OPENSUSE-SU-2021:1525-1
OPENSUSE-SU-2022:0334-1
OPENSUSE-SU-2022:23018-1
OPENSUSE-SU-2022_0334-1
OPENSUSE-SU-2022_23018-1
OPENSUSE-SU-2023_0187-1
OPENSUSE-SU-2024:11646-1
OPENSUSE-SU-2024:11647-1
OPENSUSE-SU-2024:11659-1
OPENSUSE-SU-2024:11674-1
OPENSUSE-SU-2025:15166-1
OPENSUSE-SU-2025:15589-1
RHSA-2022:0055
RHSA-2022:7457
RHSA-2022_7457
RLSA-2022:7457
SUSE-SU-2022:0213-1
SUSE-SU-2022:0334-1
SUSE-SU-2022:1507-1
SUSE-SU-2022:23018-1
SUSE-SU-2022_1507-1
SUSE-SU-2023:0187-1
SUSE-SU-2023:0326-1
SUSE-SU-2025:02282-1
SUSE-SU-2025:03540-1
SUSE-SU-2025:03545-1
SUSE-SU-2025_02282-1

Affected Products

Alt Linux
Centos
Docker
Oci Distribution Specification
Red Hat
Red Os
Rocky Linux
Suse