grafana-9.2.10-32.el8_10

エラータID: AXSA:2026-1417:20

Release date: 
Monday, August 3, 2026 - 20:24
Subject: 
grafana-9.2.10-32.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.

Security Fix(es):

* github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation (CVE-2026-44740)

Bug Fix(es) and Enhancement(s):

* [grafana / rhel-8.10.z] Remove Lua ExclusiveArch macro for Konflux build (JIRA:RHEL-188279)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-44740
Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. grafana-9.2.10-32.el8_10.src.rpm
    MD5: ff0bed19d52cba4d1fc2d88e9ec0b09c
    SHA-256: 981165603f1468b18eb37911e4c3dd5710507cecc09272b44d885632a7816f63
    Size: 326.62 MB

Asianux Server 8 for x86_64
  1. grafana-9.2.10-32.el8_10.x86_64.rpm
    MD5: 8eec2bd184c12804fca3b20ecbb44a48
    SHA-256: e7a7e53b2925841b4449b3636dca4189a14bb4e42a62e0555fbfe43d25119a76
    Size: 77.38 MB
  2. grafana-selinux-9.2.10-32.el8_10.x86_64.rpm
    MD5: 9d46e132ee4d54985182ab27f9e71339
    SHA-256: 3c7e56f356ab8a291dafaab6ba3c0b2739081deb9ec89bb2b5fdabb5d3010890
    Size: 35.86 kB