The vendor explicitly identifies these products as affected by this CVE.
- openshift-service-mesh/proxyv2-rhel9 as a component of OpenShift Service Mesh 2
- Summary
- A flaw was found in Envoy, an open source edge and service proxy. A remote attacker can exploit this vulnerability by sending a specially crafted, highly compressed zstd payload to an Envoy proxy with zstd decompression enabled. This can lead to massive memory allocation, causing severe memory exhaustion and potentially resulting in an Out-Of-Memory (OOM) kill and Denial of Service (DoS) for the Envoy proxy.
- Remediation
- See Red Hat OpenShift Service Mesh 3.0.14 documentation at https://docs.redhat.com/en/documentation/red_hat_openshift_service_mesh/3.0
