Description:
The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards.
Security Fix(es):
* mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)
* encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
* net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
* net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
* html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858)
* crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
| Architecture |
Package |
Checksum |
| aarch64 |
grafana-pcp-5.3.0-8.el10_2.1.aarch64.rpm |
e0ab7c490c4806c3a937ffa5553df06e809921816ca8972325393458b356ae78 |
| ppc64le |
grafana-pcp-5.3.0-8.el10_2.1.ppc64le.rpm |
443da1199121e4ce3d7b36dc316887714f551595ba5a9dc1c044e8394f41c577 |
| s390x |
grafana-pcp-5.3.0-8.el10_2.1.s390x.rpm |
0c62413d1bfe1afbac1dac3e3fc3f59e4dbd22bbc935a3c1b2c9371051c8e849 |
| x86_64 |
grafana-pcp-5.3.0-8.el10_2.1.x86_64.rpm |
16e36c641aa867ee6968f3cebef1f99dd436044267a6771f780746ec8417b135 |
| x86_64_v2 |
grafana-pcp-5.3.0-8.el10_2.1.x86_64_v2.rpm |
631909a235b66efb2f5ba57d98a6d9a5c55b5c2b5215072d750273ecf885ead5 |