grafana-pcp-5.1.1-16.el8_10
エラータID: AXSA:2026-1229:09
リリース日:
2026/07/09 Thursday - 19:03
題名:
grafana-pcp-5.1.1-16.el8_10
影響のあるチャネル:
Asianux Server 8 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- Golang の idna コンポーネントには、リモートの攻撃者により巧妙
に細工された Punycode ラベルを介して、特権昇格を可能とする脆弱性
が存在します。(CVE-2026-39821)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-39821
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
追加情報:
N/A
ダウンロード:
SRPMS
- grafana-pcp-5.1.1-16.el8_10.src.rpm
MD5: e630ee2c8260740db66ec4cc05f77758
SHA-256: 365c1602b41e0a716e436fc17d5cbe2794603a15f96ed6842720750b6c62d01f
Size: 60.07 MB
Asianux Server 8 for x86_64
- grafana-pcp-5.1.1-16.el8_10.x86_64.rpm
MD5: 6da402565268bd2aea69fb367ec3ce17
SHA-256: d4ac73709c31d6a5e797858b020e1259c960c9ca15ab163e879a207e30ff172b
Size: 11.23 MB