Alerts This Week
Warning Icon 1 727
Alerts This Week
Warning Icon 1 727

Red Hat OpenShift 2.4.3: RHSA-2023:5174-01 Moderate Security Issue

red hat
Calendar Grey September 14, 2023
Dist Redhat Esm H88
Important updates for Red Hat OpenShift Service Mesh's security regarding container vulnerabilities, focusing on severe security implications. Discover further details.
Red Hat OpenShift Service Mesh Containers for 2.4.3 Red Hat Product Security has rated this update as having a security impact of Moderate

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Summary

Red Hat OpenShift Service Mesh is the Red Hat distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation.
This advisory covers container images for the release.
Security Fix(es):
* envoy: gRPC access log crash caused by the listener draining (CVE-2023-35942)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2016-3709 https://access.redhat.com/security/cve/CVE-2023-2602 https://access.redhat.com/security/cve/CVE-2023-2603 https://access.redhat.com/security/cve/CVE-2023-2828 https://access.redhat.com/security/cve/CVE-2023-3899 https://access.redhat.com/security/cve/CVE-2023-27536 https://access.redhat.com/security/cve/CVE-2023-28321 https://access.redhat.com/security/cve/CVE-2023-28484 https://access.redhat.com/security/cve/CVE-2023-29469 https://access.redhat.com/security/cve/CVE-2023-32681 https://access.redhat.com/security/cve/CVE-2023-34969 https://access.redhat.com/security/cve/CVE-2023-35942 https://access.redhat.com/security/updates/classification#moderate

Package List


Advisory ID: RHSA-2023:5174-01
Product: Red Hat OpenShift Service Mesh
Issue date: 2023-09-14

Topic

Red Hat OpenShift Service Mesh Containers for 2.4.3Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Bugs Fixed

2217978 - CVE-2023-35942 envoy: gRPC access log crash caused by the listener draining

5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects):

OSSM-1182 - Deliver ARM images for OSSM Operator for Developer Preview

OSSM-3508 - Ensure Cluster Ingress Operator can create cluster-wide SMCP

OSSM-3979 - Implement envoyExtAuthzGrpc extension provider

OSSM-4247 - Service details of ServiceEntry fails

OSSM-4461 - Add FIPS annotation setting to kiali operator metadata

OSSM-4491 - Add missing configuration options to meshConfig.extensionProviders.envoyExtAuthzHttp

OSSM-4559 - Panic in conversion of extensionProviders.envoyExtAuthzHttp

OSSM-4627 - Add option to disable the GatewayClass controller

OSSM-4705 - Removing subset in config - Fails to save

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here