grafana-9.2.10-8.el8_9.ML.1

エラータID: AXSA:2024-7660:04

Release date: 
Friday, April 5, 2024 - 17:53
Subject: 
grafana-9.2.10-8.el8_9.ML.1
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Grafana is an open source, feature rich metrics dashboard and graph editor for
Graphite, InfluxDB & OpenTSDB.

Security Fix(es):

* golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA
payloads (CVE-2024-1394)

CVE-2024-1394
A memory leak flaw was found in Golang in the RSA encrypting/decrypting code,
which might lead to a resource exhaustion vulnerability using
attacker-controlled inputs​. The memory leak happens in
github.com/golang-fips/openssl/openssl/rsa.go#L113. The objects leaked are pkey​
and ctx​. That function uses named return parameters to free pkey​ and ctx​ if
there is an error initializing the context or setting the different properties.
All return statements related to error cases follow the "return nil, nil,
fail(...)" pattern, meaning that pkey​ and ctx​ will be nil inside the deferred
function that should free them.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. grafana-9.2.10-8.el8_9.ML.1.src.rpm
    MD5: 1d4d6e1f80af97aaea6934e8f7557306
    SHA-256: b033d23f619cef8617ae0d889eeffe60842fa561a542b68835c4ff4eb3a45b10
    Size: 321.66 MB

Asianux Server 8 for x86_64
  1. grafana-9.2.10-8.el8_9.ML.1.x86_64.rpm
    MD5: 0cd6db6076ecdc263863189655920733
    SHA-256: bfd0b31a264dc98c8f54f85f09c422aaa143190c87516f7a4c8a288106d3fc42
    Size: 75.99 MB