[ALSA-2026:3040] Important: grafana-pcp security update
Type:
security
Severity:
important
Release date:
2026-03-10
Description:
The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards. Security Fix(es): * crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729) * golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726) * crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 grafana-pcp-5.1.1-12.el9_7.aarch64.rpm 0e8e0ce7cecab82eb7eaaca0e572b3986ea043fcd9d065c3f6054ea437079aba
ppc64le grafana-pcp-5.1.1-12.el9_7.ppc64le.rpm 9491764306b1beb726f48d7ce8402707dcde4db22fad4bb20c6dee23c36f59a6
s390x grafana-pcp-5.1.1-12.el9_7.s390x.rpm 0c1870680bd1ae2e9d6065ccaed802df2a41707128a0e04cb6ac81cfe1437bbb
x86_64 grafana-pcp-5.1.1-12.el9_7.x86_64.rpm d916f5fe5733ef47447203f35f14989f5c8c8e064a28cd5fc2db2e5b5fb85c0f
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.