Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:47721: Important: grafana-pcp security, bug fix, and enhancement update

This update addresses multiple vulnerabilities in the grafana-pcp plugin for Red Hat Enterprise Linux 9.2, stemming from its underlying Golang components, including a critical TLS session resumption flaw (CVE-2025-68121, CVSS 10.0) and several high-severity denial-of-service issues in crypto/x509 and crypto/tls. The affected versions are those built with Golang versions earlier than 1.25.9, specifically for the CVE-2026-32281 and CVE-2026-32282 vulnerabilities. The fix is to apply the Red Hat update, which includes a rebuild of grafana-pcp with Golang 1.25.9.
Read Full Article →

Red Hat Product Errata RHSA-2026:47721 - Security Advisory Issued: 2026-07-29 Updated: 2026-07-29 RHSA-2026:47721 - Security Advisory Overview Updated Packages Synopsis Important: grafana-pcp security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for grafana-pcp is now available for Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards. Security Fix(es): crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121) crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation (CVE-2026-32281) golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) Bug Fix(es) and Enhancement(s): Rebuild grafana-pcp with golang 1.25.9 (JIRA:RHEL-191711) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux Server - AUS 9.2 x86_64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 s390x Fixes BZ - 2437111 - CVE-2025-68121 crypto/tls: crypto/tls: Incorrect certificate validation during TLS session resumption BZ - 2456333 - CVE-2026-32281 crypto/x509: golang: Go crypto/x509: Denial of Service via inefficient certificate chain validation BZ - 2456336 - CVE-2026-32282 golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root BZ - 2456338 - CVE-2026-32283 crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages BZ - 2456339 - CVE-2026-32280 crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building RHEL-191711 - Rebuild grafana-pcp with golang 1.25.9 [rhel-9.2.0.z] CVEs CVE-2025-68121 CVE-2026-32280 CVE-2026-32281 CVE-2026-32282 CVE-2026-32283 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux Server - AUS 9.2 SRPM grafana-pcp-5.1.1-5.el9_2.1.src.rpm SHA-256: 8b17cef8c75cdeb77fbc4cf9c7d7fad34fdd44bc8b9256b7b45dd1429b3878e2 x86_64 grafana-pcp-5.1.1-5.el9_2.1.x86_64.rpm SHA-256: 512330bf1b5d28c295d5c5f55b526edc74557e72abc17c50af67a02b88488fc3 grafana-pcp-debuginfo-5.1.1-5.el9_2.1.x86_64.rpm SHA-256: b188eca00b15e7ee259a442ebe7e6c6125e929d29619ab736beacb91f1893d2b grafana-pcp-debugsource-5.1.1-5.el9_2.1.x86_64.rpm SHA-256: c898e10703a7c98f73f51d26365faba4aeedf7c56f8dac466d549fe483423b1f Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.2 SRPM grafana-pcp-5.1.1-5.el9_2.1.src.rpm SHA-256: 8b17cef8c75cdeb77fbc4cf9c7d7fad34fdd44bc8b9256b7b45dd1429b3878e2 ppc64le grafana-pcp-5.1.1-5.el9_2.1.ppc64le.rpm SHA-256: ccdfcd015c7ca08cf58782e0afe476e68bf293ed742628faf4488c18b5fc05dc grafana-pcp-debuginfo-5.1.1-5.el9_2.1.ppc64le.rpm SHA-256: c7a8e0e5a2ab7679181744ce8224a03f44f01ddbf80aa4267d5c480cb0f2cc15 grafana-pcp-debugsource-5.1.1-5.el9_2.1.ppc64le.rpm SHA-256: 394a642d51ea74be73e9fcc98800758d1617918e1f5ab67817d3416e71132d7d Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.2 SRPM grafana-pcp-5.1.1-5.el9_2.1.src.rpm SHA-256: 8b17cef8c75cdeb77fbc4cf9c7d7fad34fdd44bc8b9256b7b45dd1429b3878e2 x86_64 grafana-pcp-5.1.1-5.el9_2.1.x86_64.rpm SHA-256: 512330bf1b5d28c295d5c5f55b526edc74557e72abc17c50af67a02b88488fc3 grafana-pcp-debuginfo-5.1.1-5.el9_2.1.x86_64.rpm SHA-256: b188eca00b15e7ee259a442ebe7e6c6125e929d29619ab736beacb91f1893d2b grafana-pcp-debugsource-5.1.1-5.el9_2.1.x86_64.rpm SHA-256: c898e10703a7c98f73f51d26365faba4aeedf7c56f8dac466d549fe483423b1f Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.2 SRPM grafana-pcp-5.1.1-5.el9_2.1.src.rpm SHA-256: 8b17cef8c75cdeb77fbc4cf9c7d7fad34fdd44bc8b9256b7b45dd1429b3878e2 aarch64 grafana-pcp-5.1.1-5.el9_2.1.aarch64.rpm SHA-256: d1ca39c6532eb4661f77b39f11e61e13cb57e04b6509b8ac1fc9f0a5afd371b7 grafana-pcp-debuginfo-5.1.1-5.el9_2.1.aarch64.rpm SHA-256: 9e862276dede131d6811ac1bfcaaf4abfb7f972165acd122de1010b03856e446 grafana-pcp-debugsource-5.1.1-5.el9_2.1.aarch64.rpm SHA-256: 9f4616f78ac79a8b008be1bb1118413ec77e1a09125f889d1cbb5f6aa757f86a Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.2 SRPM grafana-pcp-5.1.1-5.el9_2.1.src.rpm SHA-256: 8b17cef8c75cdeb77fbc4cf9c7d7fad34fdd44bc8b9256b7b45dd1429b3878e2 s390x grafana-pcp-5.1.1-5.el9_2.1.s390x.rpm SHA-256: b66a0de593849a1ebf15641fe8d23624c36647aa321ce112bd2e7842a38d683a grafana-pcp-debuginfo-5.1.1-5.el9_2.1.s390x.rpm SHA-256: 10008ea27f6b98b152deff94f14132af709d7ea2da219cb7bbd3aedca4a22dd9 grafana-pcp-debugsource-5.1.1-5.el9_2.1.s390x.rpm SHA-256: dcca32136f8f222624f411de5f746498eedbaf289ceff5f3eaf5edfc38e3964c Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.2 SRPM grafana-pcp-5.1.1-5.el9_2.1.src.rpm SHA-256: 8b17cef8c75cdeb77fbc4cf9c7d7fad34fdd44bc8b9256b7b45dd1429b3878e2 x86_64 grafana-pcp-5.1.1-5.el9_2.1.x86_64.rpm SHA-256: 512330bf1b5d28c295d5c5f55b526edc74557e72abc17c50af67a02b88488fc3 grafana-pcp-debuginfo-5.1.1-5.el9_2.1.x86_64.rpm SHA-256: b188eca00b15e7ee259a442ebe7e6c6125e929d29619ab736beacb91f1893d2b grafana-pcp-debugsource-5.1.1-5.el9_2.1.x86_64.rpm SHA-256: c898e10703a7c98f73f51d26365faba4aeedf7c56f8dac466d549fe483423b1f Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.2 SRPM grafana-pcp-5.1.1-5.el9_2.1.src.rpm SHA-256: 8b17cef8c75cdeb77fbc4cf9c7d7fad34fdd44bc8b9256b7b45dd1429b3878e2 aarch64 grafana-pcp-5.1.1-5.el9_2.1.aarch64.rpm SHA-256: d1ca39c6532eb4661f77b39f11e61e13cb57e04b6509b8ac1fc9f0a5afd371b7 grafana-pcp-debuginfo-5.1.1-5.el9_2.1.aarch64.rpm SHA-256: 9e862276dede131d6811ac1bfcaaf4abfb7f972165acd122de1010b03856e446 grafana-pcp-debugsource-5.1.1-5.el9_2.1.aarch64.rpm SHA-256: 9f4616f78ac79a8b008be1bb1118413ec77e1a09125f889d1cbb5f6aa757f86a Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.2 SRPM grafana-pcp-5.1.1-5.el9_2.1.src.rpm SHA-256: 8b17cef8c75cdeb77fbc4cf9c7d7fad34fdd44bc8b9256b7b45dd1429b3878e2 ppc64le grafana-pcp-5.1.1-5.el9_2.1.ppc64le.rpm SHA-256: ccdfcd015c7ca08cf58782e0afe476e68bf293ed742628faf4488c18b5fc05dc grafana-pcp-debuginfo-5.1.1-5.el9_2.1.ppc64le.rpm SHA-256: c7a8e0e5a2ab7679181744ce8224a03f44f01ddbf80aa4267d5c480cb0f2cc15 grafana-pcp-debugsource-5.1.1-5.el9_2.1.ppc64le.rpm SHA-256: 394a642d51ea74be73e9fcc98800758d1617918e1f5ab67817d3416e71132d7d Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.2 SRPM grafana-pcp-5.1.1-5.el9_2.1.src.rpm SHA-256: 8b17cef8c75cdeb77fbc4cf9c7d7fad34fdd44bc8b9256b7b45dd1429b3878e2 s390x grafana-pcp-5.1.1-5.el9_2.1.s390x.rpm SHA-256: b66a0de593849a1ebf15641fe8d23624c36647aa321ce112bd2e7842a38d683a grafana-pcp-debuginfo-5.1.1-5.el9_2.1.s390x.rpm SHA-256: 10008ea27f6b98b152deff94f14132af709d7ea2da219cb7bbd3aedca4a22dd9 grafana-pcp-debugsource-5.1.1-5.el9_2.1.s390x.rpm SHA-256: dcca32136f8f222624f411de5f746498eedbaf289ceff5f3eaf5edfc38e3964c The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article