RHSA-2025:1051: Important: Red Hat OpenShift Service Mesh Containers for 2.5.8
Important: Red Hat OpenShift Service Mesh Containers for 2.5.8
Other sources
Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation.<br>Security Fix(es):<br><li> kiali-ossmc-container: path-to-regexp Unpatched path-to-regexp ReDoS in 0.1.x (CVE-2024-52798)</li> <li> openshift-istio-kiali-rhel8-container: path-to-regexp Unpatched path-to-regexp ReDoS in 0.1.x (CVE-2024-52798)</li> <li> kiali-ossmc-container: nanoid mishandles non-integer values (CVE-2024-55565)</li> <li> openshift-istio-kiali-rhel8-container: nanoid mishandles non-integer values (CVE-2024-55565)</li> <li> openshift-istio-kiali-rhel8-container: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338)</li> <li> openshift-istio-proxyv2-rhel8-container: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338)</li> For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What are the security fixes included in RHSA-2025:1051?
RHSA-2025:1051 includes important security fixes for the kiali-ossmc-container in Red Hat OpenShift Service Mesh.
What is the severity level of RHSA-2025:1051?
The severity level of RHSA-2025:1051 is classified as important.
How can I mitigate the vulnerabilities outlined in RHSA-2025:1051?
To mitigate the vulnerabilities in RHSA-2025:1051, users should update the affected Red Hat OpenShift Service Mesh Containers to the latest version.
Which versions of Red Hat OpenShift Service Mesh are affected by RHSA-2025:1051?
RHSA-2025:1051 affects Red Hat OpenShift Service Mesh for Power, IBM Z, standard OpenShift Service Mesh, and ARM 64.
Is there a patch available for RHSA-2025:1051?
Yes, a patch is available and users are encouraged to apply it to secure their installations against the identified vulnerabilities.