RHSA-2026:49770HighCVSS 7.5

Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.4.1

Published
August 3, 2026
Last Modified
August 4, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-27145 — crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries

🎯 Affected products26

  • Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:c93cb2c93c0827d9aff606327b0a862d9df37ee819b503ccfce641ead4b56585_s390x as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:cc983205b0d67830e7207b972467318ea18c2e8fca82058ed78e5953efc09bd8_arm64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:ebfd4e4edb0bc5e7ac269999a3e2fbf0a16f077d21ad7c92bc83bb61051583e0_ppc64le as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:ff59e61200dc3a5a965e555eaec0e23a4e11ce8d23999bba23c91f0a89a76233_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:0ac49c38b56687b61e5adf6e02c4d46a164ee53e8d56814cd4708151615267dc_s390x as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:892e9a5e7bbf10a3acca5995c96d2c578b71fe0513c65ecf73753acd6fb9239d_arm64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:c6950bdd7361196349dd6f08c6e639411a09ff22faff8da6cd0e927f42a045c4_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:caf4f8b0de85da26afa6ffeae015f951d00309eaf9b04a8168324f2bff01ccea_ppc64le as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:069e61b67e8f0001090dfaffa24a916cefb410cd5b128fb24700cba00c6af93f_ppc64le as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:20e1e7bacaeecc453edbc50c82e6d7590fcb1de2e6a0802f09078b51f825d085_s390x as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:3945eae12aabfa9d2fe0af09a4153baec22957401be9e36f5d0cc3e81df3fd1c_arm64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:d3470569e40eb0a5bf6599f8cd3cbbaf321563292adea0cbbeb8b98bae4ec82d_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:8abb96980eb5a365ec7ac0d6d77e94aa60ba29a9b99960fcc8bfbe78ce541734_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:97893287c1b8b5669316edd9cfc3683981afa2f2b7b21b515ea8d786e689b434_s390x as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:dae12ab72d3b11a638770b300e43aea322473d89dcc5d50bba87c5f6210844b5_ppc64le as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:dcc6eaa106cd01bab37f82242f4d4b48dfb18348d4904122523185fbbd4dfedd_arm64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:07951fb97cb2b41cd1529dd6ec1296be383db4450916079c72df9d39d9eba1e8_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:31465f50beb7b5be5be1265037d5a6c494c153e0058d958c10696551c2b8af25_s390x as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:8bb8a88ee02c83e4aad718e6a81b60ae47329d766d1bc84dabb7447ccd2b2e6d_ppc64le as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:eb0f91c5c1f6166a49f4b30ed7d4a10c484e4dbb16bc274ea89988300907cf62_arm64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:d962ab210306e10800af7c36800d3fe5f624827635fd5a611969fc9c254552bf_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:03d82d6ae2fb57a212cb0dbd2233a6f60e910f036d05bbe27f6493763ef51c3a_s390x as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:6218984a408565bf4191827657c59d7f1af49ee9b9af155ae643a93dccc67d7c_arm64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:8a028953a98be89c25bb0301261f4e43978b8e1d9c89ebbeecce4eb7938eb7b9_amd64 as a component of Red Hat OpenShift Service Mesh 3.4
  • registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:a3ab604a154186ec0c8651de867fe07d5963a7eaa2c7fb6e3dd3102973812589_ppc64le as a component of Red Hat OpenShift Service Mesh 3.4

✅ Remediation

See Red Hat OpenShift Service Mesh 3.4.1 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.4 Workaround: A flaw was found in the Go standard library crypto/x509 package. When verifying a TLS certificate hostname, VerifyHostname processed each DNS Subject Alternative Name (SAN) entry in a loop and repeatedly split the candidate hostname on "." characters. For certificates with a very large DNS SAN list, CPU use could grow quadratically with the number of SAN entries and hostname labels. Because hostname verification runs before the certificate chain is built, this overhead can occur even when the certificate is not trusted. Red Hat rates this issue as Important. It affects Red Hat products that include the Go standard library crypto/x509 code from an affected Go toolchain version (before Go 1.25.11, or from Go 1.26.0 through Go 1.26.3). Applications and container images built with a fixed Go release (1.25.11 or later, or 1.26.4 or later) are not affected. Community distributions such as Fedora are also affected. Upstream fix: Go 1.25.11 and Go 1.26.4 (GO-2026-5037).

🔗 References (4)