grafana-9.2.10-33.el8_10

エラータID: AXSA:2026-1795:29

Release date: 
Thursday, September 10, 2026 - 10:24
Subject: 
grafana-9.2.10-33.el8_10
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.

Security Fix(es):

* net/mail: golang: net/mail: Denial of Service via pathological email address parsing (CVE-2026-42499)
* net/mail: golang: Go net/mail: Denial of Service via crafted email inputs (CVE-2026-39820)
* encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
* net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
* net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
* html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
* crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
* encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-33818
Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures.
CVE-2026-39820
Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.
CVE-2026-42499
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
CVE-2026-56853
When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client preface. ReadHeaderTimeout is unexpectedly not being applied when doing this.
CVE-2026-56858
Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.
CVE-2026-56859
Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion.
CVE-2026-56860
Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resulting in quadratic time complexity and high memory allocation overhead. Now, path resolution operates on a byte buffer using index-based backtracking for '..' segments, eliminating the quadratic time complexity and significantly reducing memory allocations.
CVE-2026-56862
Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a result, a malicious client can keep sending KeyUpdate messages to force the server to keep performing key derivation operations indefinitely.

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. grafana-9.2.10-33.el8_10.src.rpm
    MD5: b1974add3343f87237d2c684270cab31
    SHA-256: 867ab0c996399843f19fb313655c39f1556103e97dff4a9f2fdf97eee9b289c1
    Size: 326.63 MB

Asianux Server 8 for x86_64
  1. grafana-9.2.10-33.el8_10.x86_64.rpm
    MD5: 26cd8dddf2b546137ded9d83829a8975
    SHA-256: 1fd420d7ef24a145c7118c7391637fa4c6c6c0d8fb5b372e00c28054e1b7903d
    Size: 77.41 MB
  2. grafana-selinux-9.2.10-33.el8_10.x86_64.rpm
    MD5: 891edb006fb93522078fc80e85ddd9e3
    SHA-256: 0f8f803b859af03c8bdc3576c9473f895b94286a8494e38b887a454592e3568c
    Size: 36.27 kB