Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:1050 - Security Advisory
Issued:
2025-02-05
Updated:
2025-02-05

RHSA-2025:1050 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Important: Red Hat OpenShift Service Mesh Containers for 2.4.14

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Service Mesh Containers for 2.4.14

This update has a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Service Mesh is Red Hat's distribution of the Istio service mesh project, tailored for installation into an OpenShift Container Platform installation.

Security Fix(es):

  • openshift-istio-kiali-rhel8-container: Non-linear parsing of case-insensitive content in golang.org/x/net/html (CVE-2024-45338)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat OpenShift Service Mesh 2 for RHEL 8 x86_64
  • Red Hat OpenShift Service Mesh for Power 2 for RHEL 8 ppc64le
  • Red Hat OpenShift Service Mesh for IBM Z 2 for RHEL 8 s390x
  • Red Hat OpenShift Service Mesh for ARM 64 2 aarch64

Fixes

  • BZ - 2333122 - CVE-2024-45338 golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html

CVEs

  • CVE-2019-12900
  • CVE-2024-9287
  • CVE-2024-11168
  • CVE-2024-35195
  • CVE-2024-45338
  • CVE-2025-21613
  • CVE-2025-21614

References

  • https://access.redhat.com/security/updates/classification/#important

aarch64

openshift-service-mesh/grafana-rhel8@sha256:347d5c0a95a85c84f80e943bf48540c8f09806f6d9785e08ef049b2c0441e63a
openshift-service-mesh/istio-cni-rhel8@sha256:af301ce002b6b9bcadbe3c7d40d356f87849375fb6e25bb3b7be2a3327a87d8e
openshift-service-mesh/kiali-rhel8@sha256:d13f066630c536743f62e98636f462c211b71fa4ca3ab606d0d177ffb0a6f02f
openshift-service-mesh/pilot-rhel8@sha256:bf61c8797777441a6d1374708c9e514d927e8afe06112341c305488039c43a06
openshift-service-mesh/proxyv2-rhel8@sha256:6fc5598f9fe5de385397e5182acd98bf2d97286c03fae9cd9dc1379513731d5a
openshift-service-mesh/ratelimit-rhel8@sha256:52cf66418ff79ac50742bb18b09fcb1dd526d36dd404ce225eb835e207696b12

ppc64le

openshift-service-mesh/grafana-rhel8@sha256:2ef5d8f71141875e3835f3e9a40d5178c55ab6f8d0bc749993712f655880e140
openshift-service-mesh/istio-cni-rhel8@sha256:d71c0e938768d9b921b18a3ef4d63dd807b653738e2469da904e4d11349d13ce
openshift-service-mesh/kiali-rhel8@sha256:c29bc9c4a2e3e6e60c3b652abac36d522df7981a7ffa51d82a3ca0fd3bc8c6e3
openshift-service-mesh/pilot-rhel8@sha256:4d9888b16216965b8a4b4599268da1cfc3370959caf1c81aad40c98e9fd27fe4
openshift-service-mesh/proxyv2-rhel8@sha256:be984de5e04120d793ebd239b2ff13dd96fb5ef91f35e145474f7cf10e3e78bc
openshift-service-mesh/ratelimit-rhel8@sha256:be64102c8273b817c4cc1e40e598ab3c25aba7bd67d062f4bc2dc0d769f4ca92

s390x

openshift-service-mesh/grafana-rhel8@sha256:b82b62ebd62dc7ccfdea48ed9a79781fda827e842c378edb21f0a50e1957c3a1
openshift-service-mesh/istio-cni-rhel8@sha256:696f3b4e47dba74b0c0fa09d8f9ca0d93808bef46b43442fc3ed30d891e9caad
openshift-service-mesh/kiali-rhel8@sha256:19e5e7cfd27a871e3e90af68d5cfa178aa18c5c81c6058a8f979871c372da02b
openshift-service-mesh/pilot-rhel8@sha256:9f5e6fc3aaafe7e0d3ae73602d518103e6cc6c4d04d64f66d910c13c4b7152f9
openshift-service-mesh/proxyv2-rhel8@sha256:4544c22ea468034f0e0b3cddf6a3623e7fbb6dc57781303acba3444b65d96529
openshift-service-mesh/ratelimit-rhel8@sha256:d1f320a2fb040e4968fac96a3cab0b28fcfd54249d9cdb6b5abcf3117b7c950e

x86_64

openshift-service-mesh/grafana-rhel8@sha256:700d608fde7cf366a3dafe1f38d2e9127feadd9c128333c727e763fb480f94db
openshift-service-mesh/istio-cni-rhel8@sha256:134d25c125cc861192e8c4ffdfda9fe91a228a67861a2931d7ac636f49377ef1
openshift-service-mesh/kiali-rhel8@sha256:81c1d7ffe409eab23c59791d76291e5a59df44490b637e5a10ae5d6a9a95201f
openshift-service-mesh/pilot-rhel8@sha256:33ee1d2337ae8a49c130a19228d900c8300a131c2d866d2f2bcc255522792310
openshift-service-mesh/proxyv2-rhel8@sha256:94e26548521b96a26dc48d33a9e79772c237d9e7992f099adb86dc47d0887af6
openshift-service-mesh/ratelimit-rhel8@sha256:3c196a7c334d8968e7202e56777a1188a0cab9c228ecf7f2e80b8d8dd8ff3523

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility