Red Hat Product Errata RHSA-2026:46391 - Security Advisory Issued: 2026-07-27 Updated: 2026-07-27 RHSA-2026:46391 - Security Advisory Overview Updated Packages Synopsis Important: grafana security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for grafana is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation (CVE-2026-44740) Bug Fix(es) and Enhancement(s): [grafana / rhel-8.10.z] Remove Lua ExclusiveArch macro for Konflux build (JIRA:RHEL-188279) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2483894 - CVE-2026-44740 github.com/go-git/go-billy: Billy: Denial of Service via crafted input due to insufficient validation RHEL-188279 - [grafana / rhel-8.10.z] Remove Lua ExclusiveArch macro for Konflux build CVEs CVE-2026-44740 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM grafana-9.2.10-32.el8_10.src.rpm SHA-256: 06085982bd32f9c8d845e1b02c4a72cef11c5fa6883f9c1c8408255e2982d4bb x86_64 grafana-9.2.10-32.el8_10.x86_64.rpm SHA-256: 0fe22eb57eff10c1049d1b97441898741512a8b3c67d85fc407303f1ebb8fe55 grafana-debuginfo-9.2.10-32.el8_10.x86_64.rpm SHA-256: 465402503ac29dfb839810c65e67852f51cd3319701b24f46e8bbb7b1d16a77d grafana-debugsource-9.2.10-32.el8_10.x86_64.rpm SHA-256: c80fdc0237e6dc34aa27cfdeb9e42da8d9fb533d822253fce5ff905ccc92a004 grafana-selinux-9.2.10-32.el8_10.x86_64.rpm SHA-256: e6debc8ba53715c41e2f1e9d5f0e82d025d591114d5ba3b70bfd978c966062f8 Red Hat Enterprise Linux for IBM z Systems 8 SRPM grafana-9.2.10-32.el8_10.src.rpm SHA-256: 06085982bd32f9c8d845e1b02c4a72cef11c5fa6883f9c1c8408255e2982d4bb s390x grafana-9.2.10-32.el8_10.s390x.rpm SHA-256: c7591a92c8ea6b73bcc0f9553995acc9efa2de7f6f481fcee78df730f035cbdc grafana-debuginfo-9.2.10-32.el8_10.s390x.rpm SHA-256: eb455645da86f231fd56e58dbaaf02070e423dc5a29e8e0a68d9d6f253299031 grafana-debugsource-9.2.10-32.el8_10.s390x.rpm SHA-256: 159cf970ce04d2f3b50213f7fef6afae31243300c09069beb820b86cb86ebd41 grafana-selinux-9.2.10-32.el8_10.s390x.rpm SHA-256: 38174429c38425a969ba7ee5f8d52c2c3d73dfdc8a1ff63cd7b3f5ee06ae4739 Red Hat Enterprise Linux for Power, little endian 8 SRPM grafana-9.2.10-32.el8_10.src.rpm SHA-256: 06085982bd32f9c8d845e1b02c4a72cef11c5fa6883f9c1c8408255e2982d4bb ppc64le grafana-9.2.10-32.el8_10.ppc64le.rpm SHA-256: 22d304ab54cbe2d8e4a6105728991f4327de4f7fe8bef2427f8d716c5e1e277c grafana-debuginfo-9.2.10-32.el8_10.ppc64le.rpm SHA-256: 6766078a28bc32005630b08bb1c906f18b53e74f11c4ec34885f4becc7ab4bf8 grafana-debugsource-9.2.10-32.el8_10.ppc64le.rpm SHA-256: ab0f14fd00034b48b3f96a97423c1ef8b6afab2a12d0124b82fd3b4d0427f1c6 grafana-selinux-9.2.10-32.el8_10.ppc64le.rpm SHA-256: 469bbeb3e399b9822afdb88f80fe1bfd435385f47d8bbc4b49560e4d216ba1e8 Red Hat Enterprise Linux for ARM 64 8 SRPM grafana-9.2.10-32.el8_10.src.rpm SHA-256: 06085982bd32f9c8d845e1b02c4a72cef11c5fa6883f9c1c8408255e2982d4bb aarch64 grafana-9.2.10-32.el8_10.aarch64.rpm SHA-256: 5df2e5cacb2c49f39fa5d023ce84c25673a7f23d16735d0c496687170ca67e56 grafana-debuginfo-9.2.10-32.el8_10.aarch64.rpm SHA-256: d41d3aac3925ba985b6bfbdc73f5e1d7e211f5f1d6a00dacaf4090d9b3355641 grafana-debugsource-9.2.10-32.el8_10.aarch64.rpm SHA-256: 8173f041e4afb8608cda2d8fe2fb706fe2b64c3d5a0c9cfe076e9ecf5f314b2d grafana-selinux-9.2.10-32.el8_10.aarch64.rpm SHA-256: 736ec968f55203cf436989394bb17823566f49dbc88bcc219198ad6c88c240a3 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 SRPM grafana-9.2.10-32.el8_10.src.rpm SHA-256: 06085982bd32f9c8d845e1b02c4a72cef11c5fa6883f9c1c8408255e2982d4bb x86_64 grafana-9.2.10-32.el8_10.x86_64.rpm SHA-256: 0fe22eb57eff10c1049d1b97441898741512a8b3c67d85fc407303f1ebb8fe55 grafana-debuginfo-9.2.10-32.el8_10.x86_64.rpm SHA-256: 465402503ac29dfb839810c65e67852f51cd3319701b24f46e8bbb7b1d16a77d grafana-debugsource-9.2.10-32.el8_10.x86_64.rpm SHA-256: c80fdc0237e6dc34aa27cfdeb9e42da8d9fb533d822253fce5ff905ccc92a004 grafana-selinux-9.2.10-32.el8_10.x86_64.rpm SHA-256: e6debc8ba53715c41e2f1e9d5f0e82d025d591114d5ba3b70bfd978c966062f8 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 SRPM grafana-9.2.10-32.el8_10.src.rpm SHA-256: 06085982bd32f9c8d845e1b02c4a72cef11c5fa6883f9c1c8408255e2982d4bb aarch64 grafana-9.2.10-32.el8_10.aarch64.rpm SHA-256: 5df2e5cacb2c49f39fa5d023ce84c25673a7f23d16735d0c496687170ca67e56 grafana-debuginfo-9.2.10-32.el8_10.aarch64.rpm SHA-256: d41d3aac3925ba985b6bfbdc73f5e1d7e211f5f1d6a00dacaf4090d9b3355641 grafana-debugsource-9.2.10-32.el8_10.aarch64.rpm SHA-256: 8173f041e4afb8608cda2d8fe2fb706fe2b64c3d5a0c9cfe076e9ecf5f314b2d grafana-selinux-9.2.10-32.el8_10.aarch64.rpm SHA-256: 736ec968f55203cf436989394bb17823566f49dbc88bcc219198ad6c88c240a3 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 SRPM grafana-9.2.10-32.el8_10.src.rpm SHA-256: 06085982bd32f9c8d845e1b02c4a72cef11c5fa6883f9c1c8408255e2982d4bb ppc64le grafana-9.2.10-32.el8_10.ppc64le.rpm SHA-256: 22d304ab54cbe2d8e4a6105728991f4327de4f7fe8bef2427f8d716c5e1e277c grafana-debuginfo-9.2.10-32.el8_10.ppc64le.rpm SHA-256: 6766078a28bc32005630b08bb1c906f18b53e74f11c4ec34885f4becc7ab4bf8 grafana-debugsource-9.2.10-32.el8_10.ppc64le.rpm SHA-256: ab0f14fd00034b48b3f96a97423c1ef8b6afab2a12d0124b82fd3b4d0427f1c6 grafana-selinux-9.2.10-32.el8_10.ppc64le.rpm SHA-256: 469bbeb3e399b9822afdb88f80fe1bfd435385f47d8bbc4b49560e4d216ba1e8 Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 SRPM grafana-9.2.10-32.el8_10.src.rpm SHA-256: 06085982bd32f9c8d845e1b02c4a72cef11c5fa6883f9c1c8408255e2982d4bb s390x grafana-9.2.10-32.el8_10.s390x.rpm SHA-256: c7591a92c8ea6b73bcc0f9553995acc9efa2de7f6f481fcee78df730f035cbdc grafana-debuginfo-9.2.10-32.el8_10.s390x.rpm SHA-256: eb455645da86f231fd56e58dbaaf02070e423dc5a29e8e0a68d9d6f253299031 grafana-debugsource-9.2.10-32.el8_10.s390x.rpm SHA-256: 159cf970ce04d2f3b50213f7fef6afae31243300c09069beb820b86cb86ebd41 grafana-selinux-9.2.10-32.el8_10.s390x.rpm SHA-256: 38174429c38425a969ba7ee5f8d52c2c3d73dfdc8a1ff63cd7b3f5ee06ae4739 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
A Denial of Service vulnerability (CVE-2026-44740, CVSS 6.5) exists in the `github.com/go-git/go-billy` library used by Grafana, where insufficient validation of crafted input can lead to service disruption. This update addresses the issue for Grafana packages on Red Hat Enterprise Linux 8. The advisory provides updated packages to remediate the vulnerability; specific affected and fixed version ranges for the upstream Grafana application are not detailed in the provided text.