Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2023:5950 - Security Advisory
Issued:
2023-10-19
Updated:
2023-10-19

RHSA-2023:5950 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: Red Hat OpenShift Service Mesh for 2.2.11 security update

Type/Severity

Security Advisory: Important

Topic

An update is now available for Red Hat OpenShift Service Mesh 2.2 for RHEL 8.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Security Fix(es):

  • golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487) (CVE-2023-39325)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata
relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Service Mesh 2 for RHEL 8 x86_64
  • Red Hat OpenShift Service Mesh for Power 2 for RHEL 8 ppc64le
  • Red Hat OpenShift Service Mesh for IBM Z 2 for RHEL 8 s390x

Fixes

  • BZ - 2243296 - CVE-2023-39325 golang: net/http, x/net/http2: rapid stream resets can cause excessive work (CVE-2023-44487)

CVEs

  • CVE-2022-48303
  • CVE-2023-3341
  • CVE-2023-4527
  • CVE-2023-4806
  • CVE-2023-4813
  • CVE-2023-4911
  • CVE-2023-29491
  • CVE-2023-30630
  • CVE-2023-34969
  • CVE-2023-39325
  • CVE-2023-40217
  • CVE-2023-44487

References

  • https://access.redhat.com/security/updates/classification/#important
  • https://access.redhat.com/security/vulnerabilities/RHSB-2023-003

ppc64le

openshift-service-mesh/grafana-rhel8@sha256:a43e967f356eb8c3dfa082752045b4f3d3e4accaf539825487c3d9dc222e89be
openshift-service-mesh/istio-cni-rhel8@sha256:3acabc42f763763a0dd787b847b95cc851cfe1e8d0ef23e29149a406c926a5f1
openshift-service-mesh/istio-must-gather-rhel8@sha256:1d4de29ba184fba74c0a20228f02731480e08804f173f04e1c23dba55811de32
openshift-service-mesh/kiali-rhel8@sha256:d9dd763fbb43bd1db2b5c59a921b532d898dd2029c2d149fc6a3839546b30ed5
openshift-service-mesh/pilot-rhel8@sha256:319e5911c349cd8613d6a8b429b9402a7cebfcd0d7175e0bef449f0eb305643b
openshift-service-mesh/prometheus-rhel8@sha256:f1975242cf74fe2d6ab0908e04e4ea5b33c32e09112b7ef58640436e677ac9b9
openshift-service-mesh/proxyv2-rhel8@sha256:b429f0c68834e5e6dd95e9b9396980ed789302e3ab756decf00a18d9bc94a74b
openshift-service-mesh/ratelimit-rhel8@sha256:f230fe266302fde1ec9e793e8598d34a8e6814ee1641eacfb526cf67badd6642

s390x

openshift-service-mesh/grafana-rhel8@sha256:8c32a706594a914ea07519d8b8181af80d7d63f8ae16cdff00552e9bde3e04a4
openshift-service-mesh/istio-cni-rhel8@sha256:a22df732e77a5352f63c9043dc07d0ebc21aa13322d809d36c23967a748671bd
openshift-service-mesh/istio-must-gather-rhel8@sha256:8c93aafd4c2424e8cf5065aca72eae6b4fd13c701deccaa37f1c4bf241802dae
openshift-service-mesh/kiali-rhel8@sha256:e24e22e9155184d5140fb3bbea77ac91908505796f55811b4800e75445f7a20e
openshift-service-mesh/pilot-rhel8@sha256:7a2cca59e90e285eccf4f0b46786c0e653dd803091a35c3a751d12bcffe8c817
openshift-service-mesh/prometheus-rhel8@sha256:5b4a6cfe137c2fc858609f5e0bd3305cd0c8f4ad054d601f603b9d39ce335144
openshift-service-mesh/proxyv2-rhel8@sha256:23478091aeaeb3d161af0925a9b51d8b9684d08e3b3ce28f46c922c99d454b43
openshift-service-mesh/ratelimit-rhel8@sha256:e99c2da16e42573a7684c7a36ba5eafbc58101ce25c321602bac9926f37a5a28

x86_64

openshift-service-mesh/grafana-rhel8@sha256:7f58375b39ee7ed44fb1bd351f55057929fe94cc973cfae52336a3a23245308a
openshift-service-mesh/istio-cni-rhel8@sha256:1be9910498fad81c5f75b549888a1848a72025de76c7077319d88c2c01810307
openshift-service-mesh/istio-must-gather-rhel8@sha256:6a32af0e0ea904a63369444e1de9075941cda6268b6c1f3e129a2aafb2892efb
openshift-service-mesh/kiali-rhel8@sha256:957d12face152b24cf0dfbb965b3091ea75eb968e1041079986ac84ca39ed076
openshift-service-mesh/pilot-rhel8@sha256:1233216c4378bcf01dc9673856d34439ad254f3fcdc1acb584d6abe4de550da8
openshift-service-mesh/prometheus-rhel8@sha256:4a9dcc95179300d844f62e30f667965e62a86a850fd3417f422d2f72d5a8ccf5
openshift-service-mesh/proxyv2-rhel8@sha256:7d529995fe3512ce543cc612717c8c7af34a57447620e5abd749de0456a30a47
openshift-service-mesh/ratelimit-rhel8@sha256:0917002c2854e6161df80644db34e7908fd9522e56ab1a8e8865d0f4859c8880

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility