[ALSA-2026:11514] Important: grafana-pcp security update
Type:
security
Severity:
important
Release date:
2026-07-22
Description:
The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards. Security Fix(es): * golang: internal/syscall/unix: Root.Chmod can follow symlinks out of the root (CVE-2026-32282) * crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) * crypto/x509: crypto/tls: golang: Go: Denial of Service vulnerability in certificate chain building (CVE-2026-32280) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 grafana-pcp-5.1.1-14.el8_10.aarch64.rpm 35aa535cb239ec4fdfff181a1b18cd37eb7ec671eaf076b638af254d9836ccb1
ppc64le grafana-pcp-5.1.1-14.el8_10.ppc64le.rpm 7288e48ececfc68a561190261d5c9c09a2757eb4c3d44afc2dbf2ec72b0871d7
s390x grafana-pcp-5.1.1-14.el8_10.s390x.rpm 3ae809b268fcb8804e668d2b54bc8cef0acbe3af85ec33e3e94090b2cf91049f
x86_64 grafana-pcp-5.1.1-14.el8_10.x86_64.rpm ff6f8d29133476a427f1ef599108dabf722a672600b9289c3cd8aecab029b9e3
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.