grafana-pcp-5.1.1-18.el8_10

エラータID: AXSA:2026-1778:11

Release date: 
Monday, September 7, 2026 - 21:10
Subject: 
grafana-pcp-5.1.1-18.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards.

Security Fix(es):

* mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)
* encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
* net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
* net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
* html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
* crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-33818
Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
CVE-2026-42504
Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.
CVE-2026-56853
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.
CVE-2026-56858
Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.
CVE-2026-56860
Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.
CVE-2026-56862
Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. grafana-pcp-5.1.1-18.el8_10.src.rpm
    MD5: 398ec9d79bbfdd5e820577d0baa64659
    SHA-256: 1d5222ae63c9dae13c3710974ef0d443a357b324d327cecd0249214dad83526c
    Size: 60.07 MB

Asianux Server 8 for x86_64
  1. grafana-pcp-5.1.1-18.el8_10.x86_64.rpm
    MD5: 49ee40e6820759e2c6bd95194f2db830
    SHA-256: faef8230950e971a311b90bdbad9ccce29258ffcd72f841d836ed7e157a7a96f
    Size: 11.33 MB