-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

====================================================================                   Red Hat Security Advisory

Synopsis:          Moderate: Red Hat OpenShift Service Mesh Containers for 2.3.5 security update
Advisory ID:       RHSA-2023:4113-01
Product:           RHOSSM
Advisory URL:      https://access.redhat.com/errata/RHSA-2023:4113
Issue date:        2023-07-17
CVE Names:         CVE-2020-24736 CVE-2022-4304 CVE-2022-4450 
                   CVE-2022-41723 CVE-2023-0215 CVE-2023-0361 
                   CVE-2023-1667 CVE-2023-2283 CVE-2023-3089 
                   CVE-2023-24329 CVE-2023-26604 
====================================================================
1. Summary:

Red Hat OpenShift Service Mesh 2.3.5 Containers
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.

2. Description:

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio
service mesh project, tailored for installation into an on-premise
OpenShift Container Platform installation.

Security Fix(es):

* openshift: OCP & FIPS mode (CVE-2023-3089)

* net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK
decoding (CVE-2022-41723)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

3. Solution:

For details on how to apply this update, which includes the changes
described in this advisory, refer to:

https://access.redhat.com/articles/11258

4. Bugs fixed (https://bugzilla.redhat.com/):

2178358 - CVE-2022-41723 net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding
2212085 - CVE-2023-3089 openshift: OCP & FIPS mode

5. JIRA issues fixed (https://issues.redhat.com/):

OSSM-4221 - Update 2.3 base image
OSSM-4290 - Release Kiali container v1.57 for OSSM 2.3

6. References:

https://access.redhat.com/security/cve/CVE-2020-24736
https://access.redhat.com/security/cve/CVE-2022-4304
https://access.redhat.com/security/cve/CVE-2022-4450
https://access.redhat.com/security/cve/CVE-2022-41723
https://access.redhat.com/security/cve/CVE-2023-0215
https://access.redhat.com/security/cve/CVE-2023-0361
https://access.redhat.com/security/cve/CVE-2023-1667
https://access.redhat.com/security/cve/CVE-2023-2283
https://access.redhat.com/security/cve/CVE-2023-3089
https://access.redhat.com/security/cve/CVE-2023-24329
https://access.redhat.com/security/cve/CVE-2023-26604
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/security/vulnerabilities/RHSB-2023-001

7. Contact:

The Red Hat security contact is . More contact
details at https://access.redhat.com/security/team/contact/

Copyright 2023 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCAAGBQJktcNyAAoJENzjgjWX9erE4WUQAIQZTfB2us4/d8G99Djt6BBR
oXyVuskzchRvcFr6JE0NCd3uH9B17UEyqb4XsOHeZVkC9h+zZqqPwdPzXXJFUsXn
Z9cnDZniMTAS5p2ZeZ15ElXfpeojtOOFTcgCMJcYxX/YJW2R4Wk80b30IOSZnv5i
t7lG6reF7RGhNr+yzm44f4PhZa6USMI5HwMXz+WEkFj6MA2I5QDVSk1WEA3ru2Gd
4y7+9XKLRsn2M0ZwrRDivQgcyIO/2DH5tD1kROkGuzje2YCsH3Ui88KB3Qe+loLp
V4aNSJ2RuiPNnKPxa/NEIF1LgM7fUkk47fimaVHv0F0tbDyFDv6G9bOzsFFBnmEb
wXrEXvdt5BkOoIR6TTJt109VBn0Jsjhi59m8aBEuNm4HyICUz3ReS7JQNGpuxUij
xwsGqv3Wusdp12b3W8AMJIAWh8YIrEqyZ2g9NXWID8d3baRl5897OlDSoV9Y5HkE
cIumyTP0cpYbepA2ijIXZGn4EBWoDNclRxmnIHfpxZJ0dXER6Jk2ChIZp+0VZp6n
AqTOgTq2BPXDdb3XeQpFi1+dj1HW5AnRfDyLczdoR40YtEx4lg3Wt6mvAbiTnPvJ
goVbNvhRiSv+jUMWU4CH6q54Zj7ECpADNWSJ0aHxmVkAuxLq9XS83kxIXN8XhCur
2axvNkoYyccHnR17q8rR
=KGY6
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce

RedHat: RHSA-2023-4113:01 Moderate: Red Hat OpenShift Service Mesh

Red Hat OpenShift Service Mesh 2.3.5 Containers Red Hat Product Security has rated this update as having a security impact of Moderate

Summary

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation.
Security Fix(es):
* openshift: OCP & FIPS mode (CVE-2023-3089)
* net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding (CVE-2022-41723)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Summary


Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:
https://access.redhat.com/articles/11258

References

https://access.redhat.com/security/cve/CVE-2020-24736 https://access.redhat.com/security/cve/CVE-2022-4304 https://access.redhat.com/security/cve/CVE-2022-4450 https://access.redhat.com/security/cve/CVE-2022-41723 https://access.redhat.com/security/cve/CVE-2023-0215 https://access.redhat.com/security/cve/CVE-2023-0361 https://access.redhat.com/security/cve/CVE-2023-1667 https://access.redhat.com/security/cve/CVE-2023-2283 https://access.redhat.com/security/cve/CVE-2023-3089 https://access.redhat.com/security/cve/CVE-2023-24329 https://access.redhat.com/security/cve/CVE-2023-26604 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/security/vulnerabilities/RHSB-2023-001

Package List


Severity
Advisory ID: RHSA-2023:4113-01
Product: RHOSSM
Advisory URL: https://access.redhat.com/errata/RHSA-2023:4113
Issued Date: : 2023-07-17
CVE Names: CVE-2020-24736 CVE-2022-4304 CVE-2022-4450 CVE-2022-41723 CVE-2023-0215 CVE-2023-0361 CVE-2023-1667 CVE-2023-2283 CVE-2023-3089 CVE-2023-24329 CVE-2023-26604

Topic

Red Hat OpenShift Service Mesh 2.3.5 ContainersRed Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.


Topic


 

Relevant Releases Architectures


Bugs Fixed

2178358 - CVE-2022-41723 net/http, golang.org/x/net/http2: avoid quadratic complexity in HPACK decoding

2212085 - CVE-2023-3089 openshift: OCP & FIPS mode

5. JIRA issues fixed (https://issues.redhat.com/):

OSSM-4221 - Update 2.3 base image

OSSM-4290 - Release Kiali container v1.57 for OSSM 2.3


Related News