The vendor explicitly identifies these products as affected by this CVE.
- rhmtc/openshift-migration-velero-rhel8 as a component of Migration Toolkit for Containers
- knative-eventing as a component of OpenShift Serverless
- ior as a component of OpenShift Service Mesh 1
- ior.src as a component of OpenShift Service Mesh 1
- servicemesh as a component of OpenShift Service Mesh 1
- servicemesh-citadel as a component of OpenShift Service Mesh 1
- servicemesh-galley as a component of OpenShift Service Mesh 1
- servicemesh-istioctl as a component of OpenShift Service Mesh 1
- servicemesh-mixc as a component of OpenShift Service Mesh 1
- servicemesh-mixs as a component of OpenShift Service Mesh 1
- servicemesh-operator as a component of OpenShift Service Mesh 1
- servicemesh-operator.src as a component of OpenShift Service Mesh 1
- Summary
- There's an input validation flaw in golang.org/x/crypto's readCipherPacket() function. An unauthenticated attacker who sends an empty plaintext packet to a program linked with golang.org/x/crypto/ssh could cause a panic, potentially leading to denial of service.
- Remediation
- The OpenShift Service Mesh release notes provide information on the features and known issues: https://docs.openshift.com/container-platform/latest/service_mesh/v2x/servicemesh-release-notes.html
