RHSA-2022:5004CriticalCVSS 10.0

Red Hat Security Advisory: Red Hat OpenShift Service Mesh 2.1.3 security update

Published
June 13, 2022
Last Modified
August 4, 2026

🔗 CVE IDs covered (8)

📋 Description

CVE-2022-23772 — golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString CVE-2022-23773 — golang: cmd/go: misinterpretation of branch names can lead to incorrect access control CVE-2022-23806 — golang: crypto/elliptic: IsOnCurve returns true for invalid field elements CVE-2022-29224 — envoy: Segfault in GrpcHealthCheckerImpl CVE-2022-29225 — envoy: Decompressors can be zip bombed CVE-2022-29226 — envoy: oauth filter allows trivial bypass CVE-2022-29228 — envoy: oauth filter calls continueDecoding() from within decodeHeaders() CVE-2022-31045 — Istio: Unsafe memory access in metadata exchange.

🎯 Affected products37

  • OpenShift Service Mesh 2.1
  • servicemesh-0:2.1.3-1.el8.ppc64le as a component of OpenShift Service Mesh 2.1
  • servicemesh-0:2.1.3-1.el8.s390x as a component of OpenShift Service Mesh 2.1
  • servicemesh-0:2.1.3-1.el8.src as a component of OpenShift Service Mesh 2.1
  • servicemesh-0:2.1.3-1.el8.x86_64 as a component of OpenShift Service Mesh 2.1
  • servicemesh-cni-0:2.1.3-1.el8.ppc64le as a component of OpenShift Service Mesh 2.1
  • servicemesh-cni-0:2.1.3-1.el8.s390x as a component of OpenShift Service Mesh 2.1
  • servicemesh-cni-0:2.1.3-1.el8.x86_64 as a component of OpenShift Service Mesh 2.1
  • servicemesh-operator-0:2.1.3-2.el8.ppc64le as a component of OpenShift Service Mesh 2.1
  • servicemesh-operator-0:2.1.3-2.el8.s390x as a component of OpenShift Service Mesh 2.1
  • servicemesh-operator-0:2.1.3-2.el8.src as a component of OpenShift Service Mesh 2.1
  • servicemesh-operator-0:2.1.3-2.el8.x86_64 as a component of OpenShift Service Mesh 2.1
  • servicemesh-pilot-agent-0:2.1.3-1.el8.ppc64le as a component of OpenShift Service Mesh 2.1
  • servicemesh-pilot-agent-0:2.1.3-1.el8.s390x as a component of OpenShift Service Mesh 2.1
  • servicemesh-pilot-agent-0:2.1.3-1.el8.x86_64 as a component of OpenShift Service Mesh 2.1
  • servicemesh-pilot-discovery-0:2.1.3-1.el8.ppc64le as a component of OpenShift Service Mesh 2.1
  • servicemesh-pilot-discovery-0:2.1.3-1.el8.s390x as a component of OpenShift Service Mesh 2.1
  • servicemesh-pilot-discovery-0:2.1.3-1.el8.x86_64 as a component of OpenShift Service Mesh 2.1
  • servicemesh-prometheus-0:2.23.0-7.el8.ppc64le as a component of OpenShift Service Mesh 2.1
  • servicemesh-prometheus-0:2.23.0-7.el8.s390x as a component of OpenShift Service Mesh 2.1
  • servicemesh-prometheus-0:2.23.0-7.el8.src as a component of OpenShift Service Mesh 2.1
  • servicemesh-prometheus-0:2.23.0-7.el8.x86_64 as a component of OpenShift Service Mesh 2.1
  • servicemesh-proxy-0:2.1.3-1.el8.ppc64le as a component of OpenShift Service Mesh 2.1
  • servicemesh-proxy-0:2.1.3-1.el8.s390x as a component of OpenShift Service Mesh 2.1
  • servicemesh-proxy-0:2.1.3-1.el8.src as a component of OpenShift Service Mesh 2.1
  • servicemesh-proxy-0:2.1.3-1.el8.x86_64 as a component of OpenShift Service Mesh 2.1
  • servicemesh-proxy-debuginfo-0:2.1.3-1.el8.ppc64le as a component of OpenShift Service Mesh 2.1
  • servicemesh-proxy-debuginfo-0:2.1.3-1.el8.s390x as a component of OpenShift Service Mesh 2.1
  • servicemesh-proxy-debuginfo-0:2.1.3-1.el8.x86_64 as a component of OpenShift Service Mesh 2.1
  • servicemesh-proxy-debugsource-0:2.1.3-1.el8.ppc64le as a component of OpenShift Service Mesh 2.1
  • +7 more not shown

✅ Remediation

The OpenShift Service Mesh Release Notes provide information on the features and known issues. See the link in the References section. Workaround: Disable gRPC health checking and/or replace it with a different health checking type. Workaround: This can be mitigated by disabling decompression in Envoy. Workaround: There is no known mitigation for this flaw.

🔗 References (14)