[ALSA-2026:19134] Important: grafana security update
Type:
security
Severity:
important
Release date:
2026-05-26
Description:
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): * grafana: Grafana: Information disclosure of data-source passwords via public dashboards (CVE-2026-27877) * golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) * crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 grafana-selinux-10.2.6-26.el10_2.aarch64.rpm 71293f3a5340fd4cce3a18e67a9e89dec028b4dae0d1ba374821cbed66f01cfb
aarch64 grafana-10.2.6-26.el10_2.aarch64.rpm d76394f7efd931419ccf885e66e7bf4ec662b1f6ebced6bcd1d499be6d77cd42
ppc64le grafana-selinux-10.2.6-26.el10_2.ppc64le.rpm d08126460020215759b3266badca53e7e3e54f9016a10a4bcd9c0a59daad2cb1
ppc64le grafana-10.2.6-26.el10_2.ppc64le.rpm d60150c3dee80950a7494059645ee1e73a5471e94b0b5c5f2ffa1aa5590eb463
s390x grafana-10.2.6-26.el10_2.s390x.rpm 64472fc2335caba4fab3d0bd1300f3de0b6ab7e76731365e85d06e42c878d7f6
s390x grafana-selinux-10.2.6-26.el10_2.s390x.rpm 7cd33e4287322557731876040826e89c2a3ddd4009b1e39ae254ec9b7da7b37a
x86_64 grafana-selinux-10.2.6-26.el10_2.x86_64.rpm 05b7c2c7debc56987ea4810bf0a635acb444d0fc160cf44c1f5ccc841c6c9e0c
x86_64 grafana-10.2.6-26.el10_2.x86_64.rpm 1494970d1e99faa361f5d5b8c991b15845b03b92b489403a0bb338ac7281b592
x86_64_v2 grafana-10.2.6-26.el10_2.x86_64_v2.rpm 4e1aea0e082a2ee9f583d30458b6767031c90656a8ad111f8feda9ce90e0737c
x86_64_v2 grafana-selinux-10.2.6-26.el10_2.x86_64_v2.rpm 931d29261e589b6c4de4c8f822007b79ce585b85ab301f5f256752fa127eaa03
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.