Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.2.8
🔗 CVE IDs covered (7)
📋 Description
CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries CVE-2026-47204 — envoy: Envoy: Denial of Service via Connect protocol request CVE-2026-47221 — envoy: Envoy: Null pointer deref in internal redirects CVE-2026-48042 — envoy: Envoy: Denial of Service via deeply nested JSON objects CVE-2026-48044 — Envoy: Envoy: Denial of Service via specially crafted zstd payload CVE-2026-48706 — envoy: Envoy Heap Buffer Overflow in TcpStatsdSink CVE-2026-48743 — envoy: Envoy: Request desynchronization allows security policy bypass via HTTP/3 to HTTP/1 translation
🎯 Affected products26
- Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:3f2692b475ef861907674d5c76f22fd7f56bf527060e9ce2f0dcae536f00b73a_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:484d8455eff83cc16faae9da9416dee0c0eb5feed0800f935b3ae969253d300c_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:b9090e1fee37e404f53bc9451cad667bfe923e618659e4329b516c919b48361f_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:ea0fa5e8c2a020029220cb08aba52d58e0e63ec3d05fd43baa230300057b1209_s390x as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:27507de64d5f0312b2d62863516554a924846db99dee10eb2ccec11a1e0852b4_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:3bb2b62f58b2e2dc84e0b9b8a5d5eb9b499ecc5903e09e178a7e19debbf48571_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:7482725ed3fbcedf2ed0f2d5b3040e3cd2dddc02a78ba1b5a985671551bb7592_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:e449fecc4c1a0a404d0562f4a85b528eae56b304360185042f629346613aa07d_s390x as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:674c550ef82c5153fe2268016d0bb2dfb8dff149d2f593baa6e984b40800e138_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:8025cb00f7c8da8ff08f13d250951afe6147d954cf2f57dc1334231a40b6a1dc_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:c58d362396f6a2987b3e595070595694fc1bbd4f0a638ff80893ad9886a6d328_s390x as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:e09dfaf3fe80233b9db6ec431f6ceb7b06200c37d1ee2e94d6f513b4eb9fa790_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:a9893f3cced5ab9bafa20ae5f920cba27e852cc5e9f28b01a349a21d8f1ea63f_s390x as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:d689694c5d1d84b84b75ca31fd13811e8e3ad18f7d128ebf3c3f971244deb146_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:e0f294f32e31dfc832ff5a1ce8e373bbed467a1e91fc74108e9a528dbc11f541_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:f7f79b5a5021d6c045c5eba12ff8d52629b959bb5e38ebb54ac510286a354049_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:44a402ad86e142f8bc0ed42e5e15e4cfd5d259dfbb53af8462d7ba342950a8b4_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:740ceb2963af37ab11b5c107a384d7afe7a6e37e50b386408ab3ff1357c14cdf_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:9bbac11e6f4a2416a3591b3fe460a26ac564761ad383a69d34b3498375a8010c_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:a503ce7361d1ef1d369e3dd14ccdb039dc0c6b7a571a6e92b5355b2bcdce64a4_s390x as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:997b065714e98e5542db75dbbd3399719c13a302d8b3da9eb5b85600cb920bfc_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:2ed45a5174bc88d976f0a9a11c4f606a0d229bd1148e58c4a3b77fdc3b45d20e_s390x as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:8be2f6dca97556ab55f68a399ccd46a16e3f3d5dab326e0aadf4edf77c565064_amd64 as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:e7d93a618964f7db1cc188485c4f2c6822f452d646a6857b459c6703880ad72a_ppc64le as a component of Red Hat OpenShift Service Mesh 3.2
- registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:ff001786cf8dda46a48be321c46c25eeb12c33a6f80f116c35662aa20224bd7c_arm64 as a component of Red Hat OpenShift Service Mesh 3.2
✅ Remediation
See Red Hat OpenShift Service Mesh 3.2.8 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.2 Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037). Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2026:49744
- externalhttps://access.redhat.com/security/cve/CVE-2026-27145
- externalhttps://access.redhat.com/security/cve/CVE-2026-47204
- externalhttps://access.redhat.com/security/cve/CVE-2026-47221
- externalhttps://access.redhat.com/security/cve/CVE-2026-48042
- externalhttps://access.redhat.com/security/cve/CVE-2026-48044
- externalhttps://access.redhat.com/security/cve/CVE-2026-48706
- externalhttps://access.redhat.com/security/cve/CVE-2026-48743
- externalhttps://access.redhat.com/security/updates/classification/
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_49744.json