RHSA-2023:1448MediumCVSS 5.3

Red Hat Security Advisory: Red Hat OpenShift Service Mesh Containers for 2.3.2 security update

Published
March 23, 2023
Last Modified
August 19, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2022-41717 — golang: net/http: excessive memory growth in a Go server accepting HTTP/2 requests

🎯 Affected products25

  • RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/grafana-rhel8@sha256:1586092c783997486caf507909dfe82c6a73a3e236d78df0698630995654d00e_s390x as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/grafana-rhel8@sha256:b630debe0d30be952695b9eabe2ad29f614f90c9973d0c704d45cddf4dc3ad12_ppc64le as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/grafana-rhel8@sha256:fa18b7ca16b6f6bd03ba6c0fc7c647ded334c1713aeb4dde3e6e19bb153de52d_amd64 as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/istio-cni-rhel8@sha256:5e79124bf500b50aa64d74fe10e0b54063e4b2a5c9cc622ce0e513fa53f78036_s390x as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/istio-cni-rhel8@sha256:b84c8f922f4fdf1fafcc39d54f067ac2b195d5eb9a49271e7a72ee2623beee5b_amd64 as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/istio-cni-rhel8@sha256:e7208fafea3cabd16b976aba8ec649fee589477de3f85faa8c05783f4fb5222c_ppc64le as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/istio-rhel8-operator@sha256:0efbfe363d9104480489e0c431ae264f91d4ec432b1f14feccde3a3a1067013b_amd64 as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/istio-rhel8-operator@sha256:0f36d61ab5401d75c227a4b433bedc7f85f1105d91c6993f446ff16a2b61d01a_ppc64le as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/istio-rhel8-operator@sha256:c59da7a08a8d5cb7f6e55b004abf176b90b98bc9543258e193a16704fe3f3a25_s390x as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/kiali-rhel8@sha256:1794453b96ced9d22eb62b0562ceb3d313966326e1f4c58812d630c96b768a0f_amd64 as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/kiali-rhel8@sha256:598e956427dff0259d57b886c58bb0b464829c8c034b345ee65ad39d41eeaf41_s390x as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/kiali-rhel8@sha256:f20849d738ee38b5e65710c51ae30f7dd5c5e1386734e2c9d07271ae04f9de7e_ppc64le as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/pilot-rhel8@sha256:9b5baf148eb685bb0df69a0df77f1b0586d402cf4f176909ea634e68bfa03437_s390x as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/pilot-rhel8@sha256:e9a383779773f4639d5465fa207c5f90eb0e19a9e51167d3427dcf03c53786e6_ppc64le as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/pilot-rhel8@sha256:ff9420d2ba85f009dc044d50cdca7fc98fcc0bb4ee435d0099c2f5da0055d1a3_amd64 as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/prometheus-rhel8@sha256:403b41d0376cd61ad05941390a24943db7c8f7100f0f77150001bc76b744d1dd_s390x as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/prometheus-rhel8@sha256:5c52a4379e5fb1b512e312ed917347fef086c9ac9a80e8c9121a0155f4d6cfff_ppc64le as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/prometheus-rhel8@sha256:de6ccdd5ea9a2562911688db024be0d1d3c118f7d7ada739c11725689a5404ea_amd64 as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/proxyv2-rhel8@sha256:131d2f3c8fc631ddd6953ede3392eac0363a4cc485d1b11caf94c9c5572ed43c_ppc64le as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/proxyv2-rhel8@sha256:6e1500b69e5e799d70d5e89a25cb5dc92f285f0e05d5a4140a11c4aae2e1872e_amd64 as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/proxyv2-rhel8@sha256:c18406727f0b0c50873f9db2fcd9922e845bdaa0cbc35b79f70a8214e5a27359_s390x as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/ratelimit-rhel8@sha256:a98496cb8953923f0afc48ad87d22ff7ab350d96fdeaabbb9b98aefcddc73b33_amd64 as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/ratelimit-rhel8@sha256:ad56935d5b58add2e96d76217ffdc29fa86a549e95cd981e119dfe05d5d7084e_s390x as a component of RHOSSM 2.3 for RHEL 8
  • openshift-service-mesh/ratelimit-rhel8@sha256:f1c2b832d9dcda35e7eda92e3c81ad86956b8a4e02cf0fd465bc719549f8d317_ppc64le as a component of RHOSSM 2.3 for RHEL 8

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258

🔗 References (12)