Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.1.2
Red Hat OpenShift Service Mesh 3.1.2, which is based on the open source Istio project, addresses a variety of problems in a microservice architecture by creating a centralized point of control in an application. Fixes/Improvements: * Updated to Istio version 1.26.4 Security Fix(es): * istio-proxyv2-rhel9: Use after free in DNS cache (CVE-2025-54588) * istio-proxyv2-rhel9: oAuth2 Filter Signout route will not clear cookies because of missing "secure;" flag (CVE-2025-55162)
AI Analysis
Technical Summary
Red Hat OpenShift Service Mesh 3.1.2, based on Istio 1.26.4, fixes two security issues: CVE-2025-54588, a use-after-free vulnerability in the Envoy proxy's DNS cache that can lead to process crashes and potentially arbitrary code execution, and CVE-2025-55162, where the OAuth2 filter's signout route fails to clear cookies properly due to a missing "secure;" flag. The use-after-free vulnerability (CWE-416) affects memory integrity and can cause denial of service or code execution if exploited. Red Hat's advisory notes no effective mitigation other than upgrading, and no exploits are currently known in the wild. The affected versions are OpenShift Service Mesh >=3.1.0 and <3.1.2. Red Hat classifies this as a high severity issue with a CVSS base score of 7.5 (Red Hat's scoring).
Potential Impact
The use-after-free vulnerability in the Envoy proxy DNS cache can cause the proxy process to crash, resulting in denial of service. Additionally, it may allow an attacker to execute arbitrary code by exploiting memory corruption. The OAuth2 filter cookie issue could lead to cookies not being cleared securely on signout, potentially exposing session data. There are no reported active exploits in the wild. The overall impact is high due to the possibility of code execution and service disruption.
Mitigation Recommendations
Red Hat recommends upgrading affected OpenShift Service Mesh installations to version 3.1.2, which includes the fix by updating to Istio 1.26.4. No effective mitigations are currently available that meet Red Hat's criteria for ease of use and stability. Users should apply the official update to remediate these vulnerabilities.
Red Hat Security Advisory: Red Hat OpenShift Service Mesh 3.1.2
Description
Red Hat OpenShift Service Mesh 3.1.2, which is based on the open source Istio project, addresses a variety of problems in a microservice architecture by creating a centralized point of control in an application. Fixes/Improvements: * Updated to Istio version 1.26.4 Security Fix(es): * istio-proxyv2-rhel9: Use after free in DNS cache (CVE-2025-54588) * istio-proxyv2-rhel9: oAuth2 Filter Signout route will not clear cookies because of missing "secure;" flag (CVE-2025-55162)
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Red Hat OpenShift Service Mesh 3.1.2, based on Istio 1.26.4, fixes two security issues: CVE-2025-54588, a use-after-free vulnerability in the Envoy proxy's DNS cache that can lead to process crashes and potentially arbitrary code execution, and CVE-2025-55162, where the OAuth2 filter's signout route fails to clear cookies properly due to a missing "secure;" flag. The use-after-free vulnerability (CWE-416) affects memory integrity and can cause denial of service or code execution if exploited. Red Hat's advisory notes no effective mitigation other than upgrading, and no exploits are currently known in the wild. The affected versions are OpenShift Service Mesh >=3.1.0 and <3.1.2. Red Hat classifies this as a high severity issue with a CVSS base score of 7.5 (Red Hat's scoring).
Potential Impact
The use-after-free vulnerability in the Envoy proxy DNS cache can cause the proxy process to crash, resulting in denial of service. Additionally, it may allow an attacker to execute arbitrary code by exploiting memory corruption. The OAuth2 filter cookie issue could lead to cookies not being cleared securely on signout, potentially exposing session data. There are no reported active exploits in the wild. The overall impact is high due to the possibility of code execution and service disruption.
Mitigation Recommendations
Red Hat recommends upgrading affected OpenShift Service Mesh installations to version 3.1.2, which includes the fix by updating to Istio 1.26.4. No effective mitigations are currently available that meet Red Hat's criteria for ease of use and stability. Users should apply the official update to remediate these vulnerabilities.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2025:16044
- Cve Count
- 2
- Additional Cves
- ["CVE-2025-55162"]
Threat ID: 6a3de72d4853345fc1127f66
Added to database: 06/26/2026, 02:42:53 UTC
Last enriched: 08/16/2026, 15:49:22 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 47
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.