RHSA-2022:5004CriticalCVSS 10.0
Red Hat Security Advisory: Red Hat OpenShift Service Mesh 2.1.3 security update
🔗 CVE IDs covered (8)
📋 Description
CVE-2022-23772 — golang: math/big: uncontrolled memory consumption due to an unhandled overflow via Rat.SetString CVE-2022-23773 — golang: cmd/go: misinterpretation of branch names can lead to incorrect access control CVE-2022-23806 — golang: crypto/elliptic: IsOnCurve returns true for invalid field elements CVE-2022-29224 — envoy: Segfault in GrpcHealthCheckerImpl CVE-2022-29225 — envoy: Decompressors can be zip bombed CVE-2022-29226 — envoy: oauth filter allows trivial bypass CVE-2022-29228 — envoy: oauth filter calls continueDecoding() from within decodeHeaders() CVE-2022-31045 — Istio: Unsafe memory access in metadata exchange.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2022:5004
- externalhttps://access.redhat.com/security/updates/classification/#critical
- externalhttps://docs.openshift.com/container-platform/latest/service_mesh/v2x/servicemesh-release-notes.html
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053429
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053532
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2053541
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2088737
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2088738
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2088739
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2088740
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2088819
- externalhttps://issues.redhat.com/browse/OSSM-1107
- externalhttps://issues.redhat.com/browse/OSSM-1614
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_5004.json