grafana-pcp-5.1.1-14.el9_7

エラータID: AXSA:2026-539:06

Release date: 
Monday, May 4, 2026 - 18:44
Subject: 
grafana-pcp-5.1.1-14.el9_7
Affected Channels: 
MIRACLE LINUX 9 for x86_64
Severity: 
High
Description: 

The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards.

Security Fix(es):

* golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282)
* crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-32282
On Linux, if the target of Root.Chmod is replaced with a symlink while the chmod operation is in progress, Chmod can operate on the target of the symlink, even when the target lies outside the root. The Linux fchmodat syscall silently ignores the AT_SYMLINK_NOFOLLOW flag, which Root.Chmod uses to avoid symlink traversal. Root.Chmod checks its target before acting and returns an error if the target is a symlink lying outside the root, so the impact is limited to cases where the target is replaced with a symlink between the check and operation.
CVE-2026-32283
If one side of the TLS connection sends multiple key update messages post-handshake in a single record, the connection can deadlock, causing uncontrolled consumption of resources. This can lead to a denial of service. This only affects TLS 1.3.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. grafana-pcp-5.1.1-14.el9_7.src.rpm
    MD5: 58c4a9697e1d5648560440d85a3c6f59
    SHA-256: 363e848b8dc5bfc54e3e92833824603f703c9260e702a8f83d812540190013e7
    Size: 59.21 MB

Asianux Server 9 for x86_64
  1. grafana-pcp-5.1.1-14.el9_7.x86_64.rpm
    MD5: 7de2b61bb901aaf211056b613f54cc1f
    SHA-256: fc37d43a3ef08aee9f9e1cdcdd3752f79754f04311ff7d040d6766a7b934989b
    Size: 10.78 MB