grafana-pcp-5.1.1-9.el9

エラータID: AXSA:2024-9330:08

Release date: 
Thursday, December 12, 2024 - 23:15
Subject: 
grafana-pcp-5.1.1-9.el9
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards.

Security Fix(es):

* encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion (CVE-2024-34156)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2024-34156
Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion. This is a follow-up to CVE-2022-30635.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. grafana-pcp-5.1.1-9.el9.src.rpm
    MD5: bbc8411e18f16206abdf4d0a048aee38
    SHA-256: e3d7b5d76a92d2032a66354125dcdf7109190d328c4da5d48b5a4a49adbe8f8d
    Size: 59.21 MB

Asianux Server 9 for x86_64
  1. grafana-pcp-5.1.1-9.el9.x86_64.rpm
    MD5: 95308ff834c4bad0aeffe6f3946c756b
    SHA-256: 7183fc29ae35bcd089bbb013fded30644cfde98f9cc27f0f47466178d1968096
    Size: 10.40 MB