Out-of-bounds read in Istio - CVE-2022-31045
Published: June 10, 2022 / Updated: July 27, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the Ill-formed headers. A remote attacker can trigger out-of-bounds read error and cause a denial of service condition on the system.
Affected software
OpenShift Service Mesh
servicemesh-ratelimit (Red Hat package)
servicemesh-operator (Red Hat package)
servicemesh (Red Hat package)
servicemesh-proxy (Red Hat package)
servicemesh-prometheus (Red Hat package)
How to mitigate CVE-2022-31045
Install updates from vendor's website.
Note, the 1.14.2 or 1.13.6 versions are affected by this vulnerability due to process issues on the vendor's side.
OpenShift Service Mesh - update to 2.1.3
servicemesh-ratelimit (Red Hat package) - update to 2.1.3-1.el8
servicemesh-operator (Red Hat package) - update to 2.1.3-2.el8
servicemesh (Red Hat package) - update to 2.1.3-1.el8
servicemesh-proxy (Red Hat package) - update to 2.1.3-1.el8
servicemesh-prometheus (Red Hat package) - update to 2.23.0-7.el8