RHSA-2019:3041: Important: Red Hat OpenShift Service Mesh 1.0.1 RPMs
Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an on-premise OpenShift Container Platform installation.This advisory covers the RPM packages for the OpenShift Service Mesh 1.0.1 release.Security Fix(es): HTTP/2: large amount of data requests leads to denial of service (CVE-2019-9511) HTTP/2: flood using PRIORITY frames results in excessive resource consumption (CVE-2019-9513) For more details about the security issue(s), including the impact, a CVSSscore, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2019:3041?
The severity of RHSA-2019:3041 is classified as important.
How do I fix RHSA-2019:3041?
You can fix RHSA-2019:3041 by updating the affected packages to the versions specified in the advisory, specifically to 1.0.1-8.el8 for servicemesh and related packages.
Which packages are affected by RHSA-2019:3041?
RHSA-2019:3041 affects multiple packages including servicemesh, servicemesh-cni, servicemesh-prometheus, and others.
What versions of the affected packages does RHSA-2019:3041 recommend?
RHSA-2019:3041 recommends updating affected packages to versions such as 1.0.1-8.el8 for most servicemesh components.
Is RHSA-2019:3041 related to Red Hat OpenShift Service Mesh?
Yes, RHSA-2019:3041 specifically pertains to the Red Hat OpenShift Service Mesh distribution and its associated security updates.