grafana-pcp-5.1.1-14.el8_10

エラータID: AXSA:2026-569:07

リリース日: 
2026/05/08 Friday - 17:53
題名: 
grafana-pcp-5.1.1-14.el8_10
影響のあるチャネル: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards.

Security Fix(es):

* golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)
* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)
* crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-32280
During chain building, the amount of work that is done is not correctly limited when a large number of intermediate certificates are passed in VerifyOptions.Intermediates, which can lead to a denial of service. This affects both direct users of crypto/x509 and users of crypto/tls.
CVE-2026-32282
On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.
CVE-2026-32283
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

SRPMS
  1. grafana-pcp-5.1.1-14.el8_10.src.rpm
    MD5: 2823b3619ac43d3c165f37f916fdab2b
    SHA-256: 6f963fc0c39bc44977f6e3f2a020169e15bfa5eab6b646a3d2623d64082c0665
    Size: 59.22 MB

Asianux Server 8 for x86_64
  1. grafana-pcp-5.1.1-14.el8_10.x86_64.rpm
    MD5: 91eb56017ca2e909a543ca033a6bbd5a
    SHA-256: 730dc705392d63a5a4f4c5ed52edff2a606dce54b4786df61ab9ee9c3a81493c
    Size: 11.23 MB