RHSA-2020:2524: Important: Red Hat OpenShift Service Mesh 1.0 servicemesh-proxy security update
Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation.<br>Security Fix(es):<br><li> nghttp2: overly large SETTINGS frames can lead to DoS (CVE-2020-11080)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:2524?
RHSA-2020:2524 is classified as an important security fix.
How do I fix RHSA-2020:2524?
To fix RHSA-2020:2524, update the servicemesh-proxy package to version 1.0.10-3.el8.
What vulnerabilities are addressed in RHSA-2020:2524?
RHSA-2020:2524 addresses the CVE-2020-11080 vulnerability related to overly large SETTINGS frames leading to Denial of Service.
Which software is affected by RHSA-2020:2524?
The affected software for RHSA-2020:2524 is the servicemesh-proxy package in Red Hat OpenShift Service Mesh.
Is there a workaround for RHSA-2020:2524 if I cannot apply the update immediately?
There are no specific workarounds mentioned for RHSA-2020:2524, and applying the update is recommended.