grafana-pcp-5.1.1-9.el8_10

エラータID: AXSA:2024-9021:07

Release date: 
Monday, November 18, 2024 - 15:13
Subject: 
grafana-pcp-5.1.1-9.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
Moderate
Description: 

The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards.

Security Fix(es):

* golang-fips: Golang FIPS zeroed buffer (CVE-2024-9355)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-9355
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may also be possible to force a false positive match between non-equal hashes when comparing a trusted computed hmac sum to an untrusted input sum if an attacker can send a zeroed buffer in place of a pre-computed sum.  It is also possible to force a derived key to be all zeros instead of an unpredictable value.  This may have follow-on implications for the Go TLS stack.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. grafana-pcp-5.1.1-9.el8_10.src.rpm
    MD5: c24593b3c5829ed10a06e6072cd33b8a
    SHA-256: 87e4ca671642babae2fb4e65c59d99dc3a04d5eddb60130f9a443f51eca6cbf6
    Size: 59.22 MB

Asianux Server 8 for x86_64
  1. grafana-pcp-5.1.1-9.el8_10.x86_64.rpm
    MD5: c18b708360e58fa49382046165956ea8
    SHA-256: 8fda4fd08e963d6df2745b9bf123beb34b05d92e3ee1116fbd8e2786fa5d1b0d
    Size: 10.71 MB