Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:16040 - Security Advisory
Issued:
2025-09-17
Updated:
2025-09-17

RHSA-2025:16040 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Red Hat OpenShift Service Mesh 3.0.5

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Service Mesh 3.0.5
This update has a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Service Mesh 3.0.5, which is based on the open source Istio project, addresses a variety of problems in a microservice architecture by creating a centralized point of control in an application.
Security Fix(es):

  • istio-proxyv2-rhel9: Use after free in DNS cache (CVE-2025-54588)
  • istio-proxyv2-rhel9: oAuth2 Filter Signout route will not clear cookies because of missing "secure;" flag (CVE-2025-55162)

Solution

See Red Hat OpenShift Service Mesh 3.0.5 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.0

Fixes

(none)

CVEs

  • CVE-2025-54588
  • CVE-2025-55162

References

  • https://access.redhat.com/security/cve/cve-2025-54588
  • https://access.redhat.com/security/cve/cve-2025-55162
  • https://access.redhat.com/security/updates/classification
  • https://access.redhat.com/security/updates/classification/

amd64

registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:8e223a537f487bc3cef10769adc6fb619085dafe3ea797cfd52c20e3066f694f
registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:ee1d58907961191b7fcba557dcbb18a7a967bde45575a79c9cef216d1331734d
registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:01cd71a8c9bcb1691493e6997a1a501df3bdf32eca5e7fdae594de058b732983
registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:1ec528fa2769f18455ca38c2b93d9ae681069e0921101be246526831b66b161f
registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:33d11f645ea3ea208e8e8ecbad3a873361d79e5136559a5b5b07ca605d61c5d6
registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:bfb6528653e71c39a0c8b1ed5b47f470cdca34f19ea0fe97870ddf6e27b6e862
registry.redhat.io/openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9@sha256:1eec256a5d59268605828821b19dce44263d42c169adacfad2137dd410edccbb

arm64

registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:5b04637a11e755363e34f696e2c7fbc27ea770ed2c6828321e301b68f5d183a9
registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:402cc62d6d06bb9f2577f7f091696914a3db03e6a2e2817a9de30654872d1c01
registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:0ec1331194ca8632426ae63c7465a84220cdeaa9e9700ae85a291827acf3db8a
registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:473fc0e26326ea2797e6b5aa142de0713c1c1748c258e1b51995f065e1f181fa
registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:b1b03a3a39c6aac6279973e22755560138d584f1a87f0bc2333815d5e173f541
registry.redhat.io/openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9@sha256:36892a2e1f4cfdcb82121957ffa3441fe37528c4949f1458ed22f2a2af8627c0

ppc64le

registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:d9369a3ae7bed299ac7cd14326c9eb1fdd64ebf1d950ae5b232ce63ae2fdf52e
registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:478a446862338fda3a4dce3edb99723bb91198b97a6806dae510d8f2ef8f4a37
registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:ec7200c063616574ffd44fa443971f68cada6b27fad16b7baab8abb6329d0803
registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:969b56a1ff7b0bc76422c1f63fd1ef29e2f772c426324ad7c4d4f388a70c0531
registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:3759798960cd4981dba8fe934d51a439c836a0e0242fc81456304b5b13067d29
registry.redhat.io/openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9@sha256:810aee0fe85b4ff76d1d46a5397edd88bf9ff1a3852a7ace7cce34966739c00d

s390x

registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:df31246040c48c9c400d3ca3b581c60c84a54c456cbb03566afc73d480872f0b
registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:09212183f8d387781b566b15851199d57c0853cacf0e44a22294c5c9e0bec357
registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:9e756f078b3dfa923dc7e8e2cbaf4b43a82ab10f2d76cdcf8f67c12281279c31
registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:1dbcce7195f5023eef9263501240876648890a65ecd1777da728cf55fe304e64
registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:28e483cc6ded42fde9989fc16cb9a8c92750a8775b1af753e6ae7dc8ed3d379e
registry.redhat.io/openshift-service-mesh-dev-preview-beta/istio-ztunnel-rhel9@sha256:bceaa5e8fe724be4c6d86a9f0026dc63a3758129d53acfcfe57c75a2d2a0c76a

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility