[ALSA-2026:11507] Important: grafana security update
Type:
security
Severity:
important
Release date:
2026-07-22
Description:
Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): * golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) * crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) * crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 grafana-9.2.10-30.el8_10.aarch64.rpm a764cd22ee9b16f1e1b760cefd6271eb87b5f1b6cc19b87a57a1965cb26e16e1
aarch64 grafana-selinux-9.2.10-30.el8_10.aarch64.rpm ca210ae0b928c55451652be9ca13d660acb7c58d3a4b0226f2ab39c41162effa
ppc64le grafana-selinux-9.2.10-30.el8_10.ppc64le.rpm 05c235241f544264257a2fa7f156b487a30265d9a850f26780135cf72d097dff
ppc64le grafana-9.2.10-30.el8_10.ppc64le.rpm 0a797d331582c21e95ec493459fa6d89b3caa2c4ce2efdb8d4a845d756e1ec08
s390x grafana-selinux-9.2.10-30.el8_10.s390x.rpm afc6c0ff3a07d71cb92a09cc99985366dc7e7de43b62d7e217f4a489cbcd32d6
s390x grafana-9.2.10-30.el8_10.s390x.rpm d4d263bcfe471340775c9804f74019b634267921910aae4030fbdf7ac06dbe2c
x86_64 grafana-selinux-9.2.10-30.el8_10.x86_64.rpm 0ccbdf7fc4a6cfd4360c930fdd61d0a71653fb9160c093dc4e39cf7f1bf58436
x86_64 grafana-9.2.10-30.el8_10.x86_64.rpm 5fe7017b8454b2e1a6eb7b911ff75954eef4645c9e387dda715e3e8f3df910b5
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.