RHSA-2026:49770: Red Hat OpenShift Service Mesh 3.4.1
Red Hat OpenShift Service Mesh 3.4.1
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Red Hat OpenShift Service Mesh (OSSM)to a version that resolves this vulnerability.Fixed in 3.4.1 - Upgrade
Upgrade
openshift-service-mesh/istio-proxyv2-rhel9to a version that resolves this vulnerability.Patch OSSM-14933 - Upgrade
Upgrade
openshift-service-mesh/istio-pilot-rhel9to a version that resolves this vulnerability.Patch OSSM-14933 - Upgrade
Upgrade
openshift-service-mesh/istio-cni-rhel9to a version that resolves this vulnerability.Patch OSSM-14933 - Upgrade
Upgrade
openshift-service-mesh/istio-rhel9-operatorto a version that resolves this vulnerability.Patch OSSM-14933 - Compensating control
If you are affected by OSSM-14646 (istiod-default-validator points to a non-existent istiod Service after an OSSM 3.3.4 upgrade when using a non-default Istio name with the default revision tag), remediate by applying the OSSM 3.4.1 fix (OSSM-14646).
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:49770?
The severity of RHSA-2026:49770 is high with a score of 7.
What vulnerabilities are addressed in RHSA-2026:49770?
RHSA-2026:49770 addresses security issues identified by CVE-2026-27145.
How do I fix RHSA-2026:49770?
To fix RHSA-2026:49770, upgrade to the latest version of Red Hat OpenShift Service Mesh.
Which software is affected by RHSA-2026:49770?
Red Hat OpenShift Service Mesh version 3.4.1 is affected by RHSA-2026:49770.
What is the release date of RHSA-2026:49770?
RHSA-2026:49770 was published on August 3, 2026.