RHSA-2026:49765: Red Hat OpenShift Service Mesh 3.3.6
Red Hat OpenShift Service Mesh 3.3.6
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Red Hat OpenShift Service Meshto a version that resolves this vulnerability.Fixed in 3.3.6 - Upgrade
Upgrade
openshift-service-mesh/istio-proxyv2-rhel9to a version that resolves this vulnerability.Patch OSSM-14633 - Upgrade
Upgrade
openshift-service-mesh/istio-pilot-rhel9to a version that resolves this vulnerability.Patch OSSM-14633 - Upgrade
Upgrade
openshift-service-mesh/istio-cni-rhel9to a version that resolves this vulnerability.Patch OSSM-14633 - Upgrade
Upgrade
openshift-service-mesh/istio-rhel9-operatorto a version that resolves this vulnerability.Patch OSSM-14633 - Upgrade
Upgrade
openshift-service-mesh/istio-proxyv2-rhel9to a version that resolves this vulnerability.Patch OSSM-14882 - Upgrade
Upgrade
openshift-service-mesh/istio-proxyv2-rhel9to a version that resolves this vulnerability.Patch OSSM-14883 - Upgrade
Upgrade
openshift-service-mesh/istio-proxyv2-rhel9to a version that resolves this vulnerability.Patch OSSM-14884 - Upgrade
Upgrade
openshift-service-mesh/istio-proxyv2-rhel9to a version that resolves this vulnerability.Patch OSSM-14885 - Upgrade
Upgrade
openshift-service-mesh/istio-proxyv2-rhel9to a version that resolves this vulnerability.Patch OSSM-14886 - Upgrade
Upgrade
openshift-service-mesh/istio-proxyv2-rhel9to a version that resolves this vulnerability.Patch OSSM-14887 - Configuration
After upgrading to Red Hat OpenShift Service Mesh 3.3.6, ensure Istiod-default-validator is corrected so it does not point to a non-existent istiod Service after OSSM 3.3.4 upgrade when using non-default Istio name with default revision tag (OSSM-14646).
Istiod-default-validator points-to revision/service reference = non-existent istiod Service (fixed)
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:49765?
The severity of RHSA-2026:49765 is rated as high, with a score of 7.
How do I fix RHSA-2026:49765?
To fix RHSA-2026:49765, update to Red Hat OpenShift Service Mesh version 3.3.7 or later.
What vulnerabilities are addressed in RHSA-2026:49765?
RHSA-2026:49765 addresses a buffer overflow vulnerability identified as CVE-2026-27145.
When was RHSA-2026:49765 published?
RHSA-2026:49765 was published on August 3, 2026.
What software does RHSA-2026:49765 affect?
RHSA-2026:49765 affects Red Hat OpenShift Service Mesh version 3.3.6.