{"schema_version":"1.7.3","id":"SUSE-SU-2021:0445-1","published":"2021-02-12T08:15:52Z","modified":"2026-02-04T04:00:30.162867Z","related":["CVE-2020-15157","CVE-2021-21284","CVE-2021-21285"],"upstream":["CVE-2020-15157","CVE-2021-21284","CVE-2021-21285"],"summary":"Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork","details":"This update for containerd, docker, docker-runc, golang-github-docker-libnetwork fixes the following issues:\n\nUpdate Docker to 19.03.15-ce:\n\n- CVE-2021-21284: potential privilege escalation when the root user in the remapped namespace has access to the host filesystem (bsc#1181732)\n- CVE-2021-21285: malformed Docker image manifest crashes the dockerd daemon (bsc#1181730)\n- CVE-2020-15157: containerd: credentials leaking during image pull (bsc#1177598)\n","affected":[{"package":{"name":"containerd","ecosystem":"SUSE:Linux Enterprise Module for Containers 12","purl":"pkg:rpm/suse/containerd&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.3.9-16.35.1"}]}],"ecosystem_specific":{"binaries":[{"containerd":"1.3.9-16.35.1","docker":"19.03.15_ce-98.60.2","docker-libnetwork":"0.7.0.1+gitr2908_55e924b8a842-37.1","docker-runc":"1.0.0rc10+gitr3981_dc9208a3303f-1.52.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:0445-1.json"}},{"package":{"name":"docker","ecosystem":"SUSE:Linux Enterprise Module for Containers 12","purl":"pkg:rpm/suse/docker&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"19.03.15_ce-98.60.2"}]}],"ecosystem_specific":{"binaries":[{"containerd":"1.3.9-16.35.1","docker":"19.03.15_ce-98.60.2","docker-libnetwork":"0.7.0.1+gitr2908_55e924b8a842-37.1","docker-runc":"1.0.0rc10+gitr3981_dc9208a3303f-1.52.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:0445-1.json"}},{"package":{"name":"docker-runc","ecosystem":"SUSE:Linux Enterprise Module for Containers 12","purl":"pkg:rpm/suse/docker-runc&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.0rc10+gitr3981_dc9208a3303f-1.52.1"}]}],"ecosystem_specific":{"binaries":[{"containerd":"1.3.9-16.35.1","docker":"19.03.15_ce-98.60.2","docker-libnetwork":"0.7.0.1+gitr2908_55e924b8a842-37.1","docker-runc":"1.0.0rc10+gitr3981_dc9208a3303f-1.52.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:0445-1.json"}},{"package":{"name":"golang-github-docker-libnetwork","ecosystem":"SUSE:Linux Enterprise Module for Containers 12","purl":"pkg:rpm/suse/golang-github-docker-libnetwork&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Containers%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.7.0.1+gitr2908_55e924b8a842-37.1"}]}],"ecosystem_specific":{"binaries":[{"containerd":"1.3.9-16.35.1","docker":"19.03.15_ce-98.60.2","docker-libnetwork":"0.7.0.1+gitr2908_55e924b8a842-37.1","docker-runc":"1.0.0rc10+gitr3981_dc9208a3303f-1.52.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2021:0445-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2021/suse-su-20210445-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1065609"},{"type":"REPORT","url":"https://bugzilla.suse.com/1153367"},{"type":"REPORT","url":"https://bugzilla.suse.com/1157330"},{"type":"REPORT","url":"https://bugzilla.suse.com/1158590"},{"type":"REPORT","url":"https://bugzilla.suse.com/1176708"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177598"},{"type":"REPORT","url":"https://bugzilla.suse.com/1178801"},{"type":"REPORT","url":"https://bugzilla.suse.com/1180401"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181730"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181732"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-15157"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-21284"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-21285"}]}