RHSA-2022:5004: Critical: Red Hat OpenShift Service Mesh 2.1.3 security update
Red Hat OpenShift Service Mesh is a Red Hat distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation.This advisory covers the RPM packages for the release.Security Fix(es): envoy: oauth filter allows trivial bypass (CVE-2022-29226) envoy: Decompressors can be zip bombed (CVE-2022-29225) envoy: oauth filter calls continueDecoding() from within decodeHeaders() (CVE-2022-29228) golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString (CVE-2022-23772) golang: cmd/go: misinterpretation of branch names can lead to incorrect access control (CVE-2022-23773) golang: crypto/elliptic IsOnCurve returns true for invalid field elements (CVE-2022-23806) envoy: Segfault in GrpcHealthCheckerImpl (CVE-2022-29224) Istio: Unsafe memory access in metadata exchange (CVE-2022-31045) For more details about the security issues, including the impact, a CVSS score, acknowledgments, and other related information, see the CVE page listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:5004?
The severity of RHSA-2022:5004 is classified as important.
How do I fix RHSA-2022:5004?
To fix RHSA-2022:5004, upgrade to the patched versions of the affected packages specified in the advisory.
Which packages are affected by RHSA-2022:5004?
RHSA-2022:5004 affects several packages including servicemesh, servicemesh-operator, and servicemesh-proxy.
What types of systems are impacted by RHSA-2022:5004?
RHSA-2022:5004 impacts systems utilizing Red Hat OpenShift Service Mesh for on-premise installations.
Is there a specific version I need to update to for RHSA-2022:5004?
Yes, you should update to the recommended version specified in the advisory, such as 2.1.3-1.el8 for many affected packages.