grafana-pcp-5.1.1-17.el9_8
エラータID: AXSA:2026-1483:10
リリース日:
2026/08/07 Friday - 16:09
題名:
grafana-pcp-5.1.1-17.el9_8
影響のあるチャネル:
MIRACLE LINUX 9 for x86_64
Severity:
High
Description:
以下項目について対処しました。
[Security Fix]
- Golang の idna コンポーネントには、リモートの攻撃者により巧妙
に細工された Punycode ラベルを介して、特権昇格を可能とする脆弱性
が存在します。(CVE-2026-39821)
解決策:
パッケージをアップデートしてください。
CVE:
CVE-2026-39821
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
The ToASCII and ToUnicode functions incorrectly accept Punycode-encoded labels that decode to an ASCII-only label. For example, ToUnicode("xn--example-.com") incorrectly returns the name "example.com" rather than an error. This behavior can lead to privilege escalation in programs using the idna package. For example, a program which performs privilege checks on the ASCII hostname may reject "example.com" but permit "xn--example-.com". If that program subsequently converts the ASCII hostname to Unicode, it will inadvertently permits access to the Unicode name "example.com".
追加情報:
N/A
ダウンロード:
SRPMS
- grafana-pcp-5.1.1-17.el9_8.src.rpm
MD5: 7de112468855fb64ac7710f58f784ab8
SHA-256: b299b3f24bc4dcce53930536bbe0303f02986a6929f2a0ca414703df9e418242
Size: 60.06 MB
Asianux Server 9 for x86_64
- grafana-pcp-5.1.1-17.el9_8.x86_64.rpm
MD5: 9c948838e8541f1bd62133798ada262d
SHA-256: 47020fdbbca74176dd3b723f8b9ad6b80c18a3b3e1999bb997d7bb906a6ce4e9
Size: 10.86 MB