RHSA-2020:5649: Low: Red Hat OpenShift Service Mesh 1.1.11 security update
Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation.<br>Security Fix(es):<br><li> golang: data race in certain net/http servers including ReverseProxy can lead to DoS (CVE-2020-15586)</li> <li> golang: ReadUvarint and ReadVarint can read an unlimited number of bytes from invalid inputs (CVE-2020-16845)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2020:5649?
The severity of RHSA-2020:5649 is categorized as moderate.
How do I fix RHSA-2020:5649?
To fix RHSA-2020:5649, update the affected packages to the recommended versions specified in the advisory.
What software is affected by RHSA-2020:5649?
RHSA-2020:5649 affects several Red Hat OpenShift Service Mesh packages including servicemesh, servicemesh-operator, and servicemesh-prometheus.
Is RHSA-2020:5649 related to security vulnerabilities?
Yes, RHSA-2020:5649 addresses security vulnerabilities related to a data race in certain net/http servers.
What should I do if I cannot apply the update for RHSA-2020:5649?
If you cannot apply the update for RHSA-2020:5649, consider implementing mitigation strategies while working towards an update.