RHSA-2026:16505HighCVSS 8.1

Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.1.8

Published
May 12, 2026
Last Modified
August 8, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-27143 — golang: cmd/compile: possible memory corruption after bound check elimination CVE-2026-27144 — golang: cmd/compile: no-op interface conversion bypasses overlap checking CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building

🎯 Affected products26

  • Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh-tech-preview/istio-ztunnel-rhel9@sha256:44b66e1afa72c24167382ba2e71dfad9a197f4878074a8fff2e3f0ddae930e49_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh-tech-preview/istio-ztunnel-rhel9@sha256:5afab7e3267c6803839c2b96b00d715e3b327588485ecee7b23d8e3513ac15f3_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh-tech-preview/istio-ztunnel-rhel9@sha256:5e76c624c73bf4f33aed2871e03d90cd8b5fb60e56165af0f501858b47594b9f_s390x as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh-tech-preview/istio-ztunnel-rhel9@sha256:b83715ebf0a7b233b53ee600ee0062f3967bec57a84a55d0255734979a0120af_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:1164507052fa1be4b0f85d2f1474b80aa39744b6e651b3a06629980fceb44021_s390x as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:4c954b01fa50e61194c19b4ec33d72f7b2d51cb561c8553328bd087742a0915d_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:69489685a5d09b90fea6a502bfe00aa288c6e74c552469e127a5693923e0fa1e_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:989055e4981041419a61eab47e35d2e7e290855907657b32cf2de51490eafa18_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:3fce9db7529ea1b3c7b8edc40e18e6a32ccf5bb1501425ffe141837c19309287_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:6a300b4b9b1954020ba5876f91caca93ee2bc0da2c7059aaad40c3b264b59e8b_s390x as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:84558fd223caace930e314c5ad288f3680fc6d925c90409e11f85c846c211890_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:a2544534e61d95a2f5592197f70201183e5dacff68ba50aebddeb8d52219f839_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:1b9d054f45c6f2b27396c12752cce412263565a1d54220c37b6906f4049aadab_s390x as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:1fb621c913ee0b8a724852268a93a69522addeabaa3f611589c4dc8a227ab740_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:6fe2fee491444040c87cac2a9cb7e856d0c29ad02dea9e7f7490d14af120c028_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:85542d8ec656bda1029e634a6178ab9a24e608aca1470dfb45d621a78f0026ea_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:a67c6be11ac4b3fe06555c95376bd73eb367e841e87237ff3e0e66ed9479f338_s390x as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:d7016c8a7d14fe6355ad30b34a9bafca73e58beae82e2ec78abd46cda10588a0_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:d8afbf5abad2a584664f5749330ba50da76ac07d415a2fb1d070f73620e5ba90_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:e12b2cfcc3819305c9ece2e424565ca1fb7703026261db422546b76dab1c4960_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:4d96bfc97e205ba0cf2ddb03a99240fd6dd90d28bb7cdf25f0d32a99dc8891dd_arm64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:87213878db431672b26cd65a20d372866bbe7505b991483b77da8db6e9605796_s390x as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:c96e66abac88022833d4052b4a30570026878fa7912317ae2984f944bfe400e9_amd64 as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:f0f3cd9f23cf174b94120dc40999112f829a5a77b03071def745f3283cd901f7_ppc64le as a component of Red Hat OpenShift Service Mesh 3.1
  • registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:9c54dfb403dd08f7d72e066c4340d0e3143f29839d7df5485942b789f238e1ff_amd64 as a component of Red Hat OpenShift Service Mesh 3.1

✅ Remediation

See Red Hat OpenShift Service Mesh 3.1.8 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.1 Workaround: To mitigate this vulnerability, strictly sanitize and enforce bounds checking on any untrusted user input that influences loop counters, iteration limits, or memory indices. If there is no integer overflow or underflow, the out-of-bounds access cannot occur. Workaround: To mitigate this issue, review code that performs memory copies or struct assignments. If data is being passed through an interface (such as 'any' or 'interface{}') just before a move operation, refactor the code to use concrete types or explicit pointers instead.

🔗 References (10)