Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:3111 - Security Advisory
Issued:
2026-02-23
Updated:
2026-02-23

RHSA-2026:3111 - Security Advisory

  • Overview
  • Updated Images

Synopsis

Red Hat OpenShift Service Mesh 3.2.2

Type/Severity

Security Advisory: Important

Topic

Red Hat OpenShift Service Mesh 3.2.2

This update has a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat OpenShift Service Mesh 3.2.2, which is based on the open source Istio project, addresses a variety of problems in a microservice architecture by creating a centralized point of control in an application.

Fixes/Improvements:

  • Updated to Istio version 1.27.5
  • Support Gateway API Inference Extension v1.1
  • OCSP Memory Leak Check BSSL-Compatability

Security Fix(es):

  • istio-rhel9-operator: Excessive resource consumption when printing error string for host certificate validation in crypto/x509 (CVE-2025-61729)
  • istio-pilot-rhel9: Excessive resource consumption when printing error string for host certificate validation in crypto/x509 (CVE-2025-61729)
  • istio-cni-rhel9: Excessive resource consumption when printing error string for host certificate validation in crypto/x509 (CVE-2025-61729)

Solution

See Red Hat OpenShift Service Mesh 3.2.2 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.2

Affected Products

  • Red Hat OpenShift Service Mesh

Fixes

  • OSSM-11338 - Support Gateway API Inference Extension v1.1
  • OSSM-12404 - Missing tar and rsync in istio must gather image (OSSM 3)

CVEs

  • CVE-2025-61729

References

  • https://access.redhat.com/security/updates/classification
  • https://access.redhat.com/security/updates/classification/

amd64

registry.redhat.io/openshift-service-mesh/istio-sail-operator-bundle@sha256:58f26a2a054371675eb72fd922e43ec8cd5e4dfa0dff638cdb5d8c257c5541c3
registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:12ae8a08ed1d038881ab558bd620b7ca626e9888ec2e2da12abc0a986d3aafd3
registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:8a0eb5db4175afe10b3e4d2836a6fe513cb570e249face2d880362c1f4ad5a2c
registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:ef738fd2162041bdaff38185f08a6860e760eabff83644c89aa14db85a972043
registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:b78d9dc2aac659e141a2292b695881a68b4b235f4fa3e9c62324c356279ac1d2
registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:65d5217ac8cdc66e681c4bf6159f6544671fd5285fdcf014cc61828c92d3fec1
registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:df1eda79b316a9623d0c414d45df70355ce002c2461b31d9e60dc4cfea48cff0

arm64

registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:5ab43c9c4723592dea6fa8296e84b3b792db4691b734a90ce995d0dc441056e1
registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:c18d2ab6637b0b21aca15cd77cb2b7120550825c152f3208923283f5e468920f
registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:594243da2b5a4da139682f4868a7c7fd0fa56c698e54832fec05d46a72ff4dd7
registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:504818071f52813cb01d13626c96af14b88f2e235314a2450aa4f604063af1de
registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:9900c0da489c01a2e04e5c5150354dbee9b3bb46ef7b0f0072f65089997093b8
registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:9138b8828fad8bf9d335e7934f8a75fa4346d94b303ad38d67f6fed537e5f599

ppc64le

registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:67d8d5569b344c272578b4f845122d661881d0d6cacebd5f194f986060b9e10d
registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:68925d30847013b35ffe99c94e1bc36aa3f67afadaf5b178e66827123bbfede9
registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:a824e3cf232e18c87b8660f66ebdf4d13f542a928cd82b112d88b2c4deb37137
registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:cec4478a89c2efb253fe0e60553603479cf36378d00169314945f103c72353ce
registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:bc14a5012369af82b5ff8c2d9364c3ffd741a289b8431558ff7a86e022bcac6e
registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:9a4cb204e69e1c92875be27a6d7cd7cedccf7bebdcfe975988e27f049eb9a90f

s390x

registry.redhat.io/openshift-service-mesh/istio-cni-rhel9@sha256:211564de3899776d0314cfc4cb64df4835bdbdff7b494abbd91fe453842c6230
registry.redhat.io/openshift-service-mesh/istio-must-gather-rhel9@sha256:50c30e83dd8d7ca1e6fb116cbbda6f8f451dac987a49fa74689749c20022df07
registry.redhat.io/openshift-service-mesh/istio-rhel9-operator@sha256:0307adde5d8f06187c030b52aae4d89d1e66d0445f183f0c9ef4c6fe9779c506
registry.redhat.io/openshift-service-mesh/istio-pilot-rhel9@sha256:91da42912bf5a9204ce9d0a58dba1132fea18a87d3fbebaa3fa47ea8c0cd9f9c
registry.redhat.io/openshift-service-mesh/istio-proxyv2-rhel9@sha256:4f2baa3751d04f80647c3d2b51f3e1a9530c14dd0242c85dabddaedf7caacd1b
registry.redhat.io/openshift-service-mesh/istio-ztunnel-rhel9@sha256:3e44d9439468e5420742a3082b1f8b00053a02687c24bb8297825da08e92b042

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility