Statement:
OpenShift ServiceMesh (OSSM) does package a vulnerable version of luajit. However, a potential attacker would require enough privileges to be able to influence the envoy configuration to modify the lua rules in order to cause the out-of-bounds (OOB) read. Hence for OSSM the impact is low.