Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.0.11
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-27143 — golang: cmd/compile: possible memory corruption after bound check elimination CVE-2026-27144 — golang: cmd/compile: no-op interface conversion bypasses overlap checking CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building
🎯 Affected products26
- Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9@sha256:0701374518a82305e8e3102883a69fef7eb99238fe52567ae5cb3df7e2f72ee2_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9@sha256:31b7b625a2167783606bbd6d096c51eb34f492238d8d955ace6006a6eb74bcfd_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9@sha256:6f4a1fc3d4f37c9265300a32ca00fd20bc24e80cbb17d16e5c0bcc387c3afd87_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9@sha256:dcc967a82a818a4c9e41ae4c403c94cf8bfb90b67ca2e071df9f23538015440f_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:5e0473790eba6ccac07e5c83fb4cf2d1f322dea9dc522b0382f6d41219e48a41_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:a3148c276ab9ae3da2ecf3d837806e6324e5db2ac7e3c6e64dbbe107c688c695_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:d2db61a5461a9eaba5e798f007716971b17ab457dbab797b1fdac0e9a09098ff_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:d6918b3a3b427205d5b6899240f24998372600775be066ae1c52d50012d2adfe_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:2168e0ccdb4970ab8117fa1730089c712e24b8cc340c46343a6e36ad71d751f8_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:34920bc431b451274686fd0bce158c0958fc5c350991d3ce21767d64b1ba70e9_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:44826036f117f1811b24b793f48a4256b9454bc0363873881762145d2b0b312f_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:da3ac9e26e23c02f9e4f18b9fcabc894beef1f61c8df564163696b9db8bdc58d_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:100fd2b7e8adddef6271d41cd81df23a3e1bf7762638cee1ec465bccf7ab9526_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:6b0dfa1211421f2f961de8c9fdee0d00899725f8dc0fdb4eb80bb0854be90c86_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:800f35c997f822a9468c6ed993e8573b69bcd133481ea51af1542b57c1e79e5d_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:924512d5e38c14d234e9a1b11204b8877b48202faca6b07457628dfcb3f09598_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:5b1757be2b97248e70abceb263787bffe2c534cf4dcf05211fedc2834680d602_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:a07af728477ee9f405d847f1037c520a384eb5a0f53839ec3651165ca6daeba8_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:a3e492b465b7081140176024c86a8bae03902a963698978ef0de5e5adfe328ad_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:c3534c03f90d600f899e49bc0de768abf40887796942bebc37ce8f12d1e55468_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:42324c789d08d578cdb7b5791a6da546d49f545e305ea00c0adb38093b5f9f82_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:6b91cde557cb6fa93e9503291d75f8fb05d751eb93f32d8c638fb1322c9f9efd_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:7485779ebbd7b4c560844d0cc34e8ab3845a092eb45d50de6166f50e5f5ffb9b_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:877140b72711f585aaaa71c60ca4b8a885074d2be5d589668141d14c207b1f39_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:4ae9bb8293238cf21fb9f89b4fb1c21f64f7a8d2ab31bb71fee0c214ffe73c53_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
✅ Remediation
See Red Hat OpenShift Service Mesh 3.0.11 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.0 Workaround: To mitigate this vulnerability, strictly sanitize and enforce bounds checking on any untrusted user input that influences loop counters, iteration limits, or memory indices. If there is no integer overflow or underflow, the out-of-bounds access cannot occur. Workaround: To mitigate this issue, review code that performs memory copies or struct assignments. If data is being passed through an interface (such as 'any' or 'interface{}') just before a move operation, refactor the code to use concrete types or explicit pointers instead.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:16477
- externalhttps://access.redhat.com/security/cve/CVE-2026-27143
- externalhttps://access.redhat.com/security/cve/CVE-2026-27144
- externalhttps://access.redhat.com/security/cve/CVE-2026-32280
- externalhttps://access.redhat.com/security/cve/cve-2026-27143
- externalhttps://access.redhat.com/security/cve/cve-2026-27144
- externalhttps://access.redhat.com/security/cve/cve-2026-32280
- externalhttps://access.redhat.com/security/updates/classification
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_16477.json