Before applying this update, make sure all previously released errata
relevant to your system have been applied.
For details on how to apply this update, refer to:
https://access.redhat.com/articles/11258
Red Hat OpenShift Service Mesh is the Red Hat distribution of the Istio
service mesh project, tailored for installation into an on-premise
OpenShift Container Platform installation.
This advisory covers container images for the release.
Security Fix(es):
* envoy: gRPC access log crash caused by the listener draining
(CVE-2023-35942)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
https://access.redhat.com/security/cve/CVE-2016-3709 https://access.redhat.com/security/cve/CVE-2023-2602 https://access.redhat.com/security/cve/CVE-2023-2603 https://access.redhat.com/security/cve/CVE-2023-2828 https://access.redhat.com/security/cve/CVE-2023-3899 https://access.redhat.com/security/cve/CVE-2023-27536 https://access.redhat.com/security/cve/CVE-2023-28321 https://access.redhat.com/security/cve/CVE-2023-28484 https://access.redhat.com/security/cve/CVE-2023-29469 https://access.redhat.com/security/cve/CVE-2023-32681 https://access.redhat.com/security/cve/CVE-2023-34969 https://access.redhat.com/security/cve/CVE-2023-35942 https://access.redhat.com/security/updates/classification#moderate
Red Hat OpenShift Service Mesh Containers for 2.4.3Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.
2217978 - CVE-2023-35942 envoy: gRPC access log crash caused by the listener draining
5. JIRA issues fixed (https://redhat.atlassian.net/jira/projects):
OSSM-1182 - Deliver ARM images for OSSM Operator for Developer Preview
OSSM-3508 - Ensure Cluster Ingress Operator can create cluster-wide SMCP
OSSM-3979 - Implement envoyExtAuthzGrpc extension provider
OSSM-4247 - Service details of ServiceEntry fails
OSSM-4461 - Add FIPS annotation setting to kiali operator metadata
OSSM-4491 - Add missing configuration options to meshConfig.extensionProviders.envoyExtAuthzHttp
OSSM-4559 - Panic in conversion of extensionProviders.envoyExtAuthzHttp
OSSM-4627 - Add option to disable the GatewayClass controller
OSSM-4705 - Removing subset in config - Fails to save
Get the latest Linux and open source security news straight to your inbox.