VDB
RHSA-2023%3A5174
RHSA-2023%3A5174
PUBLISHED
CVSS 6.5 MEDIUM
A flaw was found in Envoy, where gRPC access loggers using the listener's global scope can cause a use-after-free crash when the listener is drained. This issue can be triggered by a listener discovery service (LDS) update with the same gRPC access log configuration.
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | openshift-service-mesh/ratelimit-rhel8@sha256:495eb5b0225e22d9ce2c8b71584513b0c1323ec208d2022735aac6d6397a68ad_amd64 as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/ratelimit-rhel8@sha256:495eb5b0225e22d9ce2c8b71584513b0c1323ec208d2022735aac6d6397a68ad_amd64 |
| Red Hat | openshift-service-mesh/kiali-rhel8-operator@sha256:047d78c2e420a442611554fd22684bd1138c2599817741323773e314c43008dc_s390x as a component of RHOSSM 2.4 for RHEL 8 | * |
| Red Hat | openshift-service-mesh/proxyv2-rhel8@sha256:356a674c259edaa6c8699e1459c168cb97d2b400b633993818abed80f78cb455_arm64 as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/proxyv2-rhel8@sha256:356a674c259edaa6c8699e1459c168cb97d2b400b633993818abed80f78cb455_arm64 |
| Red Hat | openshift-service-mesh/grafana-rhel8@sha256:6bc7fe98083324fb541ad4b02866ffee094721fc51ea0410041902ca1d8fc010_arm64 as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/grafana-rhel8@sha256:6bc7fe98083324fb541ad4b02866ffee094721fc51ea0410041902ca1d8fc010_arm64 |
| Red Hat | openshift-service-mesh/proxyv2-rhel8@sha256:45c30dca9e3f5687a3f333d29daacc8548f3f733981bc17f58c1411d844991ec_s390x as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/proxyv2-rhel8@sha256:45c30dca9e3f5687a3f333d29daacc8548f3f733981bc17f58c1411d844991ec_s390x |
| Red Hat | openshift-service-mesh/istio-cni-rhel8@sha256:c20e558ab91554c579178f9088f7a691acb557b2fc7528cf8e0768852c57e5b4_ppc64le as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/istio-cni-rhel8@sha256:c20e558ab91554c579178f9088f7a691acb557b2fc7528cf8e0768852c57e5b4_ppc64le |
| Red Hat | openshift-service-mesh/kiali-rhel8@sha256:a9d8d6b1475eb8ab1aa61d7a76ec05ddccf3f6e0e511d22a3fba308eaf5a7504_amd64 as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/kiali-rhel8@sha256:a9d8d6b1475eb8ab1aa61d7a76ec05ddccf3f6e0e511d22a3fba308eaf5a7504_amd64 |
| Red Hat | openshift-service-mesh/istio-rhel8-operator@sha256:fed31e6b657f93e080acc90fd05c5bcaf79170eecfd0fd35a7396a6d679866f6_s390x as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/istio-rhel8-operator@sha256:fed31e6b657f93e080acc90fd05c5bcaf79170eecfd0fd35a7396a6d679866f6_s390x |
| Red Hat | openshift-service-mesh/pilot-rhel8@sha256:0b5dbe4ac53ef0a926d2f8438fdd64e148585974a9d436e78cdb7615211e8a0c_arm64 as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/pilot-rhel8@sha256:0b5dbe4ac53ef0a926d2f8438fdd64e148585974a9d436e78cdb7615211e8a0c_arm64 |
| Red Hat | openshift-service-mesh/kiali-rhel8@sha256:93e94afa56baa1c81b81d935e62fd0c568d65a3ed5130e1d8ddf265d93c906d7_arm64 as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/kiali-rhel8@sha256:93e94afa56baa1c81b81d935e62fd0c568d65a3ed5130e1d8ddf265d93c906d7_arm64 |
| Red Hat | openshift-service-mesh/istio-must-gather-rhel8@sha256:1a7d34f4ae3c3629c1840491379145fa0553f53c4d1dcdcbaceaf3c536d815b6_arm64 as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/istio-must-gather-rhel8@sha256:1a7d34f4ae3c3629c1840491379145fa0553f53c4d1dcdcbaceaf3c536d815b6_arm64 |
| Red Hat | openshift-service-mesh/istio-rhel8-operator@sha256:72b732762519ad5ec504166b58a15dc5974f6250fc565f16dce98e3c9dfa0f3a_arm64 as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/istio-rhel8-operator@sha256:72b732762519ad5ec504166b58a15dc5974f6250fc565f16dce98e3c9dfa0f3a_arm64 |
| Red Hat | openshift-service-mesh/kiali-rhel8-operator@sha256:fa63641d22e2701dd06a96e09479e8d313df8d479bc1bbdbd230851eed47717a_ppc64le as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/kiali-rhel8-operator@sha256:fa63641d22e2701dd06a96e09479e8d313df8d479bc1bbdbd230851eed47717a_ppc64le |
| Red Hat | openshift-service-mesh/istio-cni-rhel8@sha256:15400b87ddb1e5c33554278802d57b8422aa88de29a3c64aa9b4452d450a87a6_s390x as a component of RHOSSM 2.4 for RHEL 8 | * |
| Red Hat | openshift-service-mesh/grafana-rhel8@sha256:6def5c25ebf96a413a8b39a1f89525c9285c47015c33937c05f17da4751d7053_ppc64le as a component of RHOSSM 2.4 for RHEL 8 | * |
| Red Hat | openshift-service-mesh/pilot-rhel8@sha256:b75907822356c05807fa0939775c74b428cf995b03f04bb298b143ddcadffc28_amd64 as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/pilot-rhel8@sha256:b75907822356c05807fa0939775c74b428cf995b03f04bb298b143ddcadffc28_amd64 |
| Red Hat | openshift-service-mesh/kiali-rhel8-operator@sha256:b01d3ef882f26764a5cfd2375bbe3e42778ca80158264e4e45297ebe0adedeb7_arm64 as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/kiali-rhel8-operator@sha256:b01d3ef882f26764a5cfd2375bbe3e42778ca80158264e4e45297ebe0adedeb7_arm64 |
| Red Hat | openshift-service-mesh/ratelimit-rhel8@sha256:ce5904e6563fef477ed2d7fd8fb5d98843ed3304d5bfb0a898ca1e8553aa7516_s390x as a component of RHOSSM 2.4 for RHEL 8 | * |
| Red Hat | openshift-service-mesh/ratelimit-rhel8@sha256:12a1e1ef1210f3cd50f0c82a0ce02101c188edde8e713d0dde88ea6f1396b479_ppc64le as a component of RHOSSM 2.4 for RHEL 8 | * |
| Red Hat | openshift-service-mesh/kiali-rhel8@sha256:956e949073b90ed152c8041380bd3c9fdc3865c593f25fb063cf7afa763e51d8_s390x as a component of RHOSSM 2.4 for RHEL 8 | openshift-service-mesh/kiali-rhel8@sha256:956e949073b90ed152c8041380bd3c9fdc3865c593f25fb063cf7afa763e51d8_s390x |
…and 16 more
Timeline
- Sep 14, 2023 CVE Published
- Apr 4, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2023:5174 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2217978 issue
- https://issues.redhat.com/browse/OSSM-1182 advisory
- https://issues.redhat.com/browse/OSSM-3508 advisory
- https://issues.redhat.com/browse/OSSM-3979 advisory
- https://issues.redhat.com/browse/OSSM-4247 advisory
- https://issues.redhat.com/browse/OSSM-4461 advisory
- https://issues.redhat.com/browse/OSSM-4491 advisory
- https://issues.redhat.com/browse/OSSM-4559 advisory
- https://issues.redhat.com/browse/OSSM-4627 advisory
- https://issues.redhat.com/browse/OSSM-4705 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_5174.json advisory
- https://access.redhat.com/security/cve/CVE-2023-35942 advisory
- https://www.cve.org/CVERecord?id=CVE-2023-35942 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-35942 advisory