RHSA-2026:16508HighCVSS 8.1

Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.2.5

Published
May 12, 2026
Last Modified
September 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-27143 — golang: cmd/compile: possible memory corruption after bound check elimination CVE-2026-27144 — golang: cmd/compile: no-op interface conversion bypasses overlap checking CVE-2026-32280 — crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building

🎯 Affected products26

  • Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:256cfb2136687be0ae8a02e3e7fc75a36c0c2b0788a739c5ff7aa1314219ba4d_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:4d2233e4df89c10c43c310e0d781966ee4beb8b8e37ee76090f5c496bddff6b3_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:4d34ee664dd9f3ce90f9a2d0910cac258b25665ef0b36c8903e2cd8315e28446_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:7ed6a92f13fc0208fe35eb3a618a362941087146e3e1ad399e1076d80ba42bff_s390x as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:60de473baf69cdcc823176b7cc76618388fc1f9cd3556bc4d28a77c299235214_s390x as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:70b4fa73f0d091371cf8564fbd6bf6819b2a8c49e44e8699753b99f8abda98aa_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:9709f44bf0c6850739e29699e842cbfe70b8f0f792567a1cd544374b64ee6576_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:f53eac2d1182a644bbbe76807a75023b59859421b91a2b828a05f0f3fe58b60a_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:266112a7cc8ce8df28b0e4a96fa5c54dfee56be8c195fd5bf576b42487c542cd_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:d4b2114dad5d5364e01021ce6f84160e70e18b98ac2819ed379aeeb9fa5db01f_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:db2ae2c246ce1864acd3e4a3923dc0388803150c270445b2f50fe0f4ee2e20a1_s390x as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:ec8bc5f9d0d9ca17a90dbbc7c734db2b439674686062e9a27d63145618f31926_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:0f6be50e399ab621f779541aa3ad1ebb4ffbaa3527079fa0342e6c809957d7d7_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:37f3f3c7d0a9d2441b76a32da94e8c69f2845dc15e82cf90afccf48026c4df86_s390x as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:9b84f3435deb230347504f0e27383f5907a16a47cbb14e57d163ac507677126b_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:a6672d63cee00907fdccb9d1996d633edffd768d66d35d60cb0a234ba3df5194_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:4ba0d15d8f4af2d653866fc5a58fc2740afbc663ab7e6179908611ec33f8bc3b_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:a03fcf7c240381f444b19e1149e5e506d41f6b8e3ee8d85e53e8db21d38bb6f1_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:d38aa16bf2c6d89b78143242e9e77770c62a4842f60760ac1c1c5a8bfb75031a_s390x as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:ffc5dbc4cf0e9bfb12246d08f6653f35baba6df9f632f165c23a9d47c09d2dfb_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:b5c6f18442fe408343552a4dc240b4b24921013159407fd908c073f17a0593cd_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:393c3aae7f14f978611cdc1e176b4603abae3848bf51a2944f5ad616c51f6ab8_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:9bf5745846bb21b33adddaa26abf24597bfb6f2597cf93351741d648b4532016_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:e27229b0de83ec1868d162a934b4f0e60b5b9716d82365842e5a8b3fecc021ce_s390x as a component of Red Hat OpenShift Service Mesh 3.2
  • registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:ec36a4ce06c963a52ae150f95489a2ba5e3aa351c730f727665ffae0eb15afc4_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2

✅ Remediation

See Red Hat OpenShift Service Mesh 3.2.5 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.2 Workaround: To mitigate this vulnerability, strictly sanitize and enforce bounds checking on any untrusted user input that influences loop counters, iteration limits, or memory indices. If there is no integer overflow or underflow, the out-of-bounds access cannot occur. Workaround: To mitigate this issue, review code that performs memory copies or struct assignments. If data is being passed through an interface (such as 'any' or 'interface{}') just before a move operation, refactor the code to use concrete types or explicit pointers instead.

🔗 References (10)