Red Hat Product Errata RHSA-2026:35826 - Security Advisory Issued: 2026-07-06 Updated: 2026-07-06 RHSA-2026:35826 - Security Advisory Overview Updated Packages Synopsis Important: grafana-pcp security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for grafana-pcp is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards. Security Fix(es): golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2480756 - CVE-2026-39821 golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVEs CVE-2026-39821 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM grafana-pcp-5.3.0-7.el10_2.src.rpm SHA-256: 1a541f503e6d8174af0523a43188770450737e7e3a15faa12b99aaf4061568c0 x86_64 grafana-pcp-5.3.0-7.el10_2.x86_64.rpm SHA-256: f01c22a22aa174db7be0ecd57f5fdbed7da7d01f4829dcc84633567d4c819373 grafana-pcp-debuginfo-5.3.0-7.el10_2.x86_64.rpm SHA-256: 8d1d0ae53b5f65611c0c3bc96185a08516719ce66d58f35ca13bc453419a8549 grafana-pcp-debugsource-5.3.0-7.el10_2.x86_64.rpm SHA-256: 743acee0ab91e514998ff758e7e46d3c9daa4f24a9ddcca2ee33c129de338747 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM grafana-pcp-5.3.0-7.el10_2.src.rpm SHA-256: 1a541f503e6d8174af0523a43188770450737e7e3a15faa12b99aaf4061568c0 x86_64 grafana-pcp-5.3.0-7.el10_2.x86_64.rpm SHA-256: f01c22a22aa174db7be0ecd57f5fdbed7da7d01f4829dcc84633567d4c819373 grafana-pcp-debuginfo-5.3.0-7.el10_2.x86_64.rpm SHA-256: 8d1d0ae53b5f65611c0c3bc96185a08516719ce66d58f35ca13bc453419a8549 grafana-pcp-debugsource-5.3.0-7.el10_2.x86_64.rpm SHA-256: 743acee0ab91e514998ff758e7e46d3c9daa4f24a9ddcca2ee33c129de338747 Red Hat Enterprise Linux for IBM z Systems 10 SRPM grafana-pcp-5.3.0-7.el10_2.src.rpm SHA-256: 1a541f503e6d8174af0523a43188770450737e7e3a15faa12b99aaf4061568c0 s390x grafana-pcp-5.3.0-7.el10_2.s390x.rpm SHA-256: 01e6b8fb95f82000bd32a0053770225c94d6dcfd4661766646cfd1f06ca24560 grafana-pcp-debuginfo-5.3.0-7.el10_2.s390x.rpm SHA-256: 484f66eac447aff42ec7ba57b4d4a407a4fa095882efa06e52294eb87bbc27be grafana-pcp-debugsource-5.3.0-7.el10_2.s390x.rpm SHA-256: 8231092e2c3789eb4786dae162511ade84c7212c921c9eafe4a3cdfec269e940 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 SRPM grafana-pcp-5.3.0-7.el10_2.src.rpm SHA-256: 1a541f503e6d8174af0523a43188770450737e7e3a15faa12b99aaf4061568c0 s390x grafana-pcp-5.3.0-7.el10_2.s390x.rpm SHA-256: 01e6b8fb95f82000bd32a0053770225c94d6dcfd4661766646cfd1f06ca24560 grafana-pcp-debuginfo-5.3.0-7.el10_2.s390x.rpm SHA-256: 484f66eac447aff42ec7ba57b4d4a407a4fa095882efa06e52294eb87bbc27be grafana-pcp-debugsource-5.3.0-7.el10_2.s390x.rpm SHA-256: 8231092e2c3789eb4786dae162511ade84c7212c921c9eafe4a3cdfec269e940 Red Hat Enterprise Linux for Power, little endian 10 SRPM grafana-pcp-5.3.0-7.el10_2.src.rpm SHA-256: 1a541f503e6d8174af0523a43188770450737e7e3a15faa12b99aaf4061568c0 ppc64le grafana-pcp-5.3.0-7.el10_2.ppc64le.rpm SHA-256: 4adda5652914174ddeca36bdef38f3a387a7316ce764a49ecfc4d83274863cc2 grafana-pcp-debuginfo-5.3.0-7.el10_2.ppc64le.rpm SHA-256: f95492c63030f3f54024df515e058abf816c5505798913cd5f87536613025630 grafana-pcp-debugsource-5.3.0-7.el10_2.ppc64le.rpm SHA-256: 974828f0256eb2e174c5692df90fc47dbf22bc87e92f27703c80c4720588d8c7 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 SRPM grafana-pcp-5.3.0-7.el10_2.src.rpm SHA-256: 1a541f503e6d8174af0523a43188770450737e7e3a15faa12b99aaf4061568c0 ppc64le grafana-pcp-5.3.0-7.el10_2.ppc64le.rpm SHA-256: 4adda5652914174ddeca36bdef38f3a387a7316ce764a49ecfc4d83274863cc2 grafana-pcp-debuginfo-5.3.0-7.el10_2.ppc64le.rpm SHA-256: f95492c63030f3f54024df515e058abf816c5505798913cd5f87536613025630 grafana-pcp-debugsource-5.3.0-7.el10_2.ppc64le.rpm SHA-256: 974828f0256eb2e174c5692df90fc47dbf22bc87e92f27703c80c4720588d8c7 Red Hat Enterprise Linux for ARM 64 10 SRPM grafana-pcp-5.3.0-7.el10_2.src.rpm SHA-256: 1a541f503e6d8174af0523a43188770450737e7e3a15faa12b99aaf4061568c0 aarch64 grafana-pcp-5.3.0-7.el10_2.aarch64.rpm SHA-256: 114f6aad7492d94ac46ba26b39b57a1afde6f0e3102822ce45e415b4dff4abdb grafana-pcp-debuginfo-5.3.0-7.el10_2.aarch64.rpm SHA-256: cb93a632940f7019a3f84b456cb3850e2997e7897760a479951ae01ee64e87b7 grafana-pcp-debugsource-5.3.0-7.el10_2.aarch64.rpm SHA-256: ffa7729d809b57366b6afb86fb9d0acd0af6a3634d6875540164978843ed5ef0 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 SRPM grafana-pcp-5.3.0-7.el10_2.src.rpm SHA-256: 1a541f503e6d8174af0523a43188770450737e7e3a15faa12b99aaf4061568c0 aarch64 grafana-pcp-5.3.0-7.el10_2.aarch64.rpm SHA-256: 114f6aad7492d94ac46ba26b39b57a1afde6f0e3102822ce45e415b4dff4abdb grafana-pcp-debuginfo-5.3.0-7.el10_2.aarch64.rpm SHA-256: cb93a632940f7019a3f84b456cb3850e2997e7897760a479951ae01ee64e87b7 grafana-pcp-debugsource-5.3.0-7.el10_2.aarch64.rpm SHA-256: ffa7729d809b57366b6afb86fb9d0acd0af6a3634d6875540164978843ed5ef0 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 SRPM grafana-pcp-5.3.0-7.el10_2.src.rpm SHA-256: 1a541f503e6d8174af0523a43188770450737e7e3a15faa12b99aaf4061568c0 aarch64 grafana-pcp-5.3.0-7.el10_2.aarch64.rpm SHA-256: 114f6aad7492d94ac46ba26b39b57a1afde6f0e3102822ce45e415b4dff4abdb grafana-pcp-debuginfo-5.3.0-7.el10_2.aarch64.rpm SHA-256: cb93a632940f7019a3f84b456cb3850e2997e7897760a479951ae01ee64e87b7 grafana-pcp-debugsource-5.3.0-7.el10_2.aarch64.rpm SHA-256: ffa7729d809b57366b6afb86fb9d0acd0af6a3634d6875540164978843ed5ef0 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 SRPM grafana-pcp-5.3.0-7.el10_2.src.rpm SHA-256: 1a541f503e6d8174af0523a43188770450737e7e3a15faa12b99aaf4061568c0 s390x grafana-pcp-5.3.0-7.el10_2.s390x.rpm SHA-256: 01e6b8fb95f82000bd32a0053770225c94d6dcfd4661766646cfd1f06ca24560 grafana-pcp-debuginfo-5.3.0-7.el10_2.s390x.rpm SHA-256: 484f66eac447aff42ec7ba57b4d4a407a4fa095882efa06e52294eb87bbc27be grafana-pcp-debugsource-5.3.0-7.el10_2.s390x.rpm SHA-256: 8231092e2c3789eb4786dae162511ade84c7212c921c9eafe4a3cdfec269e940 Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 SRPM grafana-pcp-5.3.0-7.el10_2.src.rpm SHA-256: 1a541f503e6d8174af0523a43188770450737e7e3a15faa12b99aaf4061568c0 ppc64le grafana-pcp-5.3.0-7.el10_2.ppc64le.rpm SHA-256: 4adda5652914174ddeca36bdef38f3a387a7316ce764a49ecfc4d83274863cc2 grafana-pcp-debuginfo-5.3.0-7.el10_2.ppc64le.rpm SHA-256: f95492c63030f3f54024df515e058abf816c5505798913cd5f87536613025630 grafana-pcp-debugsource-5.3.0-7.el10_2.ppc64le.rpm SHA-256: 974828f0256eb2e174c5692df90fc47dbf22bc87e92f27703c80c4720588d8c7 Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 SRPM grafana-pcp-5.3.0-7.el10_2.src.rpm SHA-256: 1a541f503e6d8174af0523a43188770450737e7e3a15faa12b99aaf4061568c0 x86_64 grafana-pcp-5.3.0-7.el10_2.x86_64.rpm SHA-256: f01c22a22aa174db7be0ecd57f5fdbed7da7d01f4829dcc84633567d4c819373 grafana-pcp-debuginfo-5.3.0-7.el10_2.x86_64.rpm SHA-256: 8d1d0ae53b5f65611c0c3bc96185a08516719ce66d58f35ca13bc453419a8549 grafana-pcp-debugsource-5.3.0-7.el10_2.x86_64.rpm SHA-256: 743acee0ab91e514998ff758e7e46d3c9daa4f24a9ddcca2ee33c129de338747 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 SRPM grafana-pcp-5.3.0-7.el10_2.src.rpm SHA-256: 1a541f503e6d8174af0523a43188770450737e7e3a15faa12b99aaf4061568c0 x86_64 grafana-pcp-5.3.0-7.el10_2.x86_64.rpm SHA-256: f01c22a22aa174db7be0ecd57f5fdbed7da7d01f4829dcc84633567d4c819373 grafana-pcp-debuginfo-5.3.0-7.el10_2.x86_64.rpm SHA-256: 8d1d0ae53b5f65611c0c3bc96185a08516719ce66d58f35ca13bc453419a8549 grafana-pcp-debugsource-5.3.0-7.el10_2.x86_64.rpm SHA-256: 743acee0ab91e514998ff758e7e46d3c9daa4f24a9ddcca2ee33c129de338747 Red Hat Enterprise Linux for ARM 64 - Ext
A critical vulnerability (CVE-2026-39821, CVSS 9.6) in the golang.org/x/net/idna library allows privilege escalation via incorrect Punycode label processing. This flaw affects the grafana-pcp plugin for Red Hat Enterprise Linux 10, specifically through versions of the underlying Go net library prior to 0.55.0. The fix is included in the updated grafana-pcp packages for RHEL 10.