Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.0.14
🔗 CVE IDs covered (5)
📋 Description
CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-47204 — envoy: Envoy: Denial of Service via Connect protocol request CVE-2026-47221 — envoy: Envoy: Null pointer deref in internal redirects CVE-2026-48042 — envoy: Envoy: Denial of Service via deeply nested JSON objects CVE-2026-48044 — Envoy: Envoy: Denial of Service via specially crafted zstd payload
🎯 Affected products26
- Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9@sha256:36b3c326e2fba0b8824c5dbf59cfb7d959210d1a4db5f3916c1cb45e60d84ad2_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9@sha256:4198b046dac61c231cef9bbd9fb46c471398dd35810b8f5529127bcdca17b984_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9@sha256:c470def3c88ed1fc0b9910b661dc5868eae2d9b98e3716708ed2e20e5c394864_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9@sha256:ca7c68ead0366eb0403b66501d3b36b6b6943e1f03ad715152d24574bf0ea27f_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:1db5c7b66608f7115d5d1a754db2a6671d29d3c74409d49f0569172f2a93ea23_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:2d59e8a82176436d26d5901f4ded8a96a69c21a7b6ba2a44236ac3e7fd13803c_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:c495aca6fdf9ce0b918a25dcf945d60ce48b123f3e62aad7c6050d12b233f8fc_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:fc11bcd756930e9a924f3c393c64b3d05f4042c905c64ba4abe6daea6d162b5c_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:84ef5bcb35860861c56db161d1f58eee93da60e8ae567ab99b0f490ed99d005e_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:881ea7b69aab940e260e2c30a14ac238a48a932a4151f456612e99113bf56d60_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:a5c0a575e5006cb54ed0d1bd010a89ee77a255d75261c066cc86500cffa15809_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:b0c4f45a65a299dde118b0218f15c6ddaeb4445a72a01d9599f1058a23b7b6ea_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:2cfe598f59d5d8ab5db3b282f8855e308ec3464a59a3c1fda8c060e89d810fbd_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:43600305cb1d27e91499edcf019e6ec37ed76044b1c0c7f2a38d563f33ff7621_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:474b1618ff7b83f00fa32498a0e804139d6e75965822467374390f24189cf05a_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:a32dc6e5e586953fed9aa5eceee97885fc8a9a9fb095fc5125da1f53707d92c1_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:59fa6f408b345a25d7e9dd12cf79c5e56cae7a7c2d814ef32512346021485060_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:cd1e969fed2cc48c6b2b2e911164bba8294bce35b5e386d64729296aed5a31e7_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:e1de2591216c2b907756cb1589e5257469e358ec26fd54355a9e2adb492854fd_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:e2de4e2eaa221b5942369955da3a1a0eaf3076ef444dafc36739481ef0c583ef_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:2321852a236377f6dc7149fe410ba711eb86868270b8dddc61d0b4dbbbd012ad_arm64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:464a08aa193402064fca7c03c56f4e207ad4cf8367b65b5fa8dc76ed8295d943_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:4a999a30d276b344a48829b9a23df39df129bd4b5d9c9e50400e9f5d0cc6da47_s390x as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:f5a42a94174b608ec70cf1d455e3af1b2fe2a53d4a4c635fd8ccf246c606c4db_ppc64le as a component of Red Hat OpenShift Service Mesh 3.0
- registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:d78a3d9a4719160ff763ba5da4dcacec0724e3772f9e4e8923b73f1d6bd0c501_amd64 as a component of Red Hat OpenShift Service Mesh 3.0
✅ Remediation
See Red Hat OpenShift Service Mesh 3.0.14 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.0 Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (8)
- selfhttps://access.redhat.com/errata/RHSA-2026:49705
- externalhttps://access.redhat.com/security/cve/CVE-2026-27145
- externalhttps://access.redhat.com/security/cve/CVE-2026-47204
- externalhttps://access.redhat.com/security/cve/CVE-2026-47221
- externalhttps://access.redhat.com/security/cve/CVE-2026-48042
- externalhttps://access.redhat.com/security/cve/CVE-2026-48044
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_49705.json