Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Red Hat OpenShift Service Mesh 2.1.2: RHSA-2022:1275-01 Critical Update

red hat
Calendar Grey April 7, 2022
Dist Redhat Esm H88
We are excited to announce a significant enhancement for Red Hat OpenShift Service Mesh 2.1.2 that resolves multiple security vulnerabilities with critical ramifications.
Red Hat OpenShift Service Mesh 2.1.2 Red Hat Product Security has rated this update as having a security impact of Important

Solution

The OpenShift Service Mesh Release Notes provide information on the features and known issues:

https://docs.redhat.com/en/documentation/openshift_container_platform/4.15/html/service_mesh/service-mesh-2-x

Summary

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation.
This advisory covers the RPM packages for the release.
Security Fix(es):
* envoy: Incorrect configuration handling allows mTLS session re-use without re-validation (CVE-2022-21654)
* envoy: Incorrect handling of internal redirects to routes with a direct response entry (CVE-2022-21655)
* istio: Unauthenticated control plane denial of service attack due to stack exhaustion (CVE-2022-24726)
* envoy: Null pointer dereference when using JWT filter safe_regex match (CVE-2021-43824)
* envoy: Use-after-free when response filters increase response data (CVE-2021-43825)
* envoy: Use-after-free when tunneling TCP over HTTP (CVE-2021-43826)
* envoy: Stack exhaustion when a cluster is deleted via Cluster Discovery Service (CVE-2022-23606)
* istio: unauthenticated control plane denial of service attack (CVE-2022-23635)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2021-43824 https://access.redhat.com/security/cve/CVE-2021-43825 https://access.redhat.com/security/cve/CVE-2021-43826 https://access.redhat.com/security/cve/CVE-2022-21654 https://access.redhat.com/security/cve/CVE-2022-21655 https://access.redhat.com/security/cve/CVE-2022-23606 https://access.redhat.com/security/cve/CVE-2022-23635 https://access.redhat.com/security/cve/CVE-2022-24726 https://access.redhat.com/security/updates/classification#important

Package List

OpenShift Service Mesh 2.1:
Source: servicemesh-2.1.2-4.el8.src.rpm servicemesh-operator-2.1.2-4.el8.src.rpm servicemesh-prometheus-2.23.0-5.el8.src.rpm servicemesh-proxy-2.1.2-4.el8.src.rpm servicemesh-ratelimit-2.1.2-4.el8.src.rpm
noarch: servicemesh-proxy-wasm-2.1.2-4.el8.noarch.rpm
ppc64le: servicemesh-2.1.2-4.el8.ppc64le.rpm servicemesh-cni-2.1.2-4.el8.ppc64le.rpm servicemesh-operator-2.1.2-4.el8.ppc64le.rpm servicemesh-pilot-agent-2.1.2-4.el8.ppc64le.rpm servicemesh-pilot-discovery-2.1.2-4.el8.ppc64le.rpm servicemesh-prometheus-2.23.0-5.el8.ppc64le.rpm servicemesh-proxy-2.1.2-4.el8.ppc64le.rpm servicemesh-proxy-debuginfo-2.1.2-4.el8.ppc64le.rpm servicemesh-proxy-debugsource-2.1.2-4.el8.ppc64le.rpm servicemesh-ratelimit-2.1.2-4.el8.ppc64le.rpm
s390x: servicemesh-2.1.2-4.el8.s390x.rpm servicemesh-cni-2.1.2-4.el8.s390x.rpm servicemesh-operator-2.1.2-4.el8.s390x.rpm servicemesh-pilot-agent-2.1.2-4.el8.s390x.rpm servicemesh-pilot-discovery-2.1.2-4.el8.s390x.rpm servicemesh-prometheus-2.23.0-5.el8.s390x.rpm servicemesh-proxy-2.1.2-4.el8.s390x.rpm servicemesh-proxy-debuginfo-2.1.2-4.el8.s390x.rpm servicemesh-proxy-debugsource-2.1.2-4.el8.s390x.rpm servicemesh-ratelimit-2.1.2-4.el8.s390x.rpm
x86_64: servicemesh-2.1.2-4.el8.x86_64.rpm

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2022:1275-01
Product: Red Hat OpenShift Service Mesh
Issue date: 2022-04-07

Topic

Red Hat OpenShift Service Mesh 2.1.2Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.

Relevant Releases Architectures

OpenShift Service Mesh 2.1 - noarch, ppc64le, s390x, x86_64

Bugs Fixed

2050744 - CVE-2021-43824 envoy: Null pointer dereference when using JWT filter safe_regex match

2050746 - CVE-2021-43825 envoy: Use-after-free when response filters increase response data

2050748 - CVE-2021-43826 envoy: Use-after-free when tunneling TCP over HTTP

2050753 - CVE-2022-21654 envoy: Incorrect configuration handling allows mTLS session re-use without re-validation

2050757 - CVE-2022-21655 envoy: Incorrect handling of internal redirects to routes with a direct response entry

2050758 - CVE-2022-23606 envoy: Stack exhaustion when a cluster is deleted via Cluster Discovery Service

2057277 - CVE-2022-23635 istio: unauthenticated control plane denial of service attack

2061638 - CVE-2022-24726 istio: Unauthenticated control plane denial of service attack due to stack exhaustion

6. JIRA issues fixed (https://redhat.atlassian.net/jira/projects):

OSSM-1074 - Pod annotations defined in SMCP are not injected in the pods

OSSM-1234 - RPM Release for Maistra 2.1.2

OSSM-303 - Control Openshift Route Creation for ingress Gateways

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here