Red Hat Product Errata RHSA-2026:35829 - Security Advisory Issued: 2026-07-06 Updated: 2026-07-06 RHSA-2026:35829 - Security Advisory Overview Updated Packages Synopsis Important: grafana-pcp security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for grafana-pcp is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards. Security Fix(es): golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2480756 - CVE-2026-39821 golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVEs CVE-2026-39821 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM grafana-pcp-5.1.1-17.el9_8.src.rpm SHA-256: 856c8dc3196ff776060222f24c179f9d34bf10e99a277622802f324c02946e79 x86_64 grafana-pcp-5.1.1-17.el9_8.x86_64.rpm SHA-256: 60fb49276ab4869b1bf9789d6878b8c5e449cdd0391fb36647d3fff6c8923a24 grafana-pcp-debuginfo-5.1.1-17.el9_8.x86_64.rpm SHA-256: 00f9f5867e820e15c1fc13bee6e7c01b7d08290110908682ac8852e8c08aa0c7 grafana-pcp-debugsource-5.1.1-17.el9_8.x86_64.rpm SHA-256: 787d81cb2e9b81f69892adca81b58a95bbce204f40c0e0ce455de319f819576d Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM grafana-pcp-5.1.1-17.el9_8.src.rpm SHA-256: 856c8dc3196ff776060222f24c179f9d34bf10e99a277622802f324c02946e79 x86_64 grafana-pcp-5.1.1-17.el9_8.x86_64.rpm SHA-256: 60fb49276ab4869b1bf9789d6878b8c5e449cdd0391fb36647d3fff6c8923a24 grafana-pcp-debuginfo-5.1.1-17.el9_8.x86_64.rpm SHA-256: 00f9f5867e820e15c1fc13bee6e7c01b7d08290110908682ac8852e8c08aa0c7 grafana-pcp-debugsource-5.1.1-17.el9_8.x86_64.rpm SHA-256: 787d81cb2e9b81f69892adca81b58a95bbce204f40c0e0ce455de319f819576d Red Hat Enterprise Linux for IBM z Systems 9 SRPM grafana-pcp-5.1.1-17.el9_8.src.rpm SHA-256: 856c8dc3196ff776060222f24c179f9d34bf10e99a277622802f324c02946e79 s390x grafana-pcp-5.1.1-17.el9_8.s390x.rpm SHA-256: cb26eb89cee4761a376ab6d800c152c7491b819162f3380f86514ec147560061 grafana-pcp-debuginfo-5.1.1-17.el9_8.s390x.rpm SHA-256: fba3fea3f247725a7b3fcbc20c004cbf60780c47f2a22e9c4ddb4687a642b69a grafana-pcp-debugsource-5.1.1-17.el9_8.s390x.rpm SHA-256: 41501af92f35f20e282c463b92ee2afd2c366160b5760e8271567e77adc22f80 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 SRPM grafana-pcp-5.1.1-17.el9_8.src.rpm SHA-256: 856c8dc3196ff776060222f24c179f9d34bf10e99a277622802f324c02946e79 s390x grafana-pcp-5.1.1-17.el9_8.s390x.rpm SHA-256: cb26eb89cee4761a376ab6d800c152c7491b819162f3380f86514ec147560061 grafana-pcp-debuginfo-5.1.1-17.el9_8.s390x.rpm SHA-256: fba3fea3f247725a7b3fcbc20c004cbf60780c47f2a22e9c4ddb4687a642b69a grafana-pcp-debugsource-5.1.1-17.el9_8.s390x.rpm SHA-256: 41501af92f35f20e282c463b92ee2afd2c366160b5760e8271567e77adc22f80 Red Hat Enterprise Linux for Power, little endian 9 SRPM grafana-pcp-5.1.1-17.el9_8.src.rpm SHA-256: 856c8dc3196ff776060222f24c179f9d34bf10e99a277622802f324c02946e79 ppc64le grafana-pcp-5.1.1-17.el9_8.ppc64le.rpm SHA-256: e7b692c8d0e729aea0f7db93470de56926b542bec23a75e7f3c8ffdb36327ed4 grafana-pcp-debuginfo-5.1.1-17.el9_8.ppc64le.rpm SHA-256: cfc2e1f0da6ecbdcc878fb844b631d3c58d97a6b1603bf59d03605c70e8b4c8c grafana-pcp-debugsource-5.1.1-17.el9_8.ppc64le.rpm SHA-256: d1965986151e0ce76717ee6bc15c99b5fdadcc625b30b37574da410e6d4c4f78 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 SRPM grafana-pcp-5.1.1-17.el9_8.src.rpm SHA-256: 856c8dc3196ff776060222f24c179f9d34bf10e99a277622802f324c02946e79 ppc64le grafana-pcp-5.1.1-17.el9_8.ppc64le.rpm SHA-256: e7b692c8d0e729aea0f7db93470de56926b542bec23a75e7f3c8ffdb36327ed4 grafana-pcp-debuginfo-5.1.1-17.el9_8.ppc64le.rpm SHA-256: cfc2e1f0da6ecbdcc878fb844b631d3c58d97a6b1603bf59d03605c70e8b4c8c grafana-pcp-debugsource-5.1.1-17.el9_8.ppc64le.rpm SHA-256: d1965986151e0ce76717ee6bc15c99b5fdadcc625b30b37574da410e6d4c4f78 Red Hat Enterprise Linux for ARM 64 9 SRPM grafana-pcp-5.1.1-17.el9_8.src.rpm SHA-256: 856c8dc3196ff776060222f24c179f9d34bf10e99a277622802f324c02946e79 aarch64 grafana-pcp-5.1.1-17.el9_8.aarch64.rpm SHA-256: c39cb22b6ec086ae88d10c66863cb71fefe0b477dc69b4a816d2d4af769f2c5c grafana-pcp-debuginfo-5.1.1-17.el9_8.aarch64.rpm SHA-256: 2260bbb2f57e304a828f70970df7308365b83ebff7b6eade8e9104dae4da5739 grafana-pcp-debugsource-5.1.1-17.el9_8.aarch64.rpm SHA-256: 9f1c7c903961903b1bb95a970951f1c770d1392e1091e7f47cb20be4fe831618 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 SRPM grafana-pcp-5.1.1-17.el9_8.src.rpm SHA-256: 856c8dc3196ff776060222f24c179f9d34bf10e99a277622802f324c02946e79 aarch64 grafana-pcp-5.1.1-17.el9_8.aarch64.rpm SHA-256: c39cb22b6ec086ae88d10c66863cb71fefe0b477dc69b4a816d2d4af769f2c5c grafana-pcp-debuginfo-5.1.1-17.el9_8.aarch64.rpm SHA-256: 2260bbb2f57e304a828f70970df7308365b83ebff7b6eade8e9104dae4da5739 grafana-pcp-debugsource-5.1.1-17.el9_8.aarch64.rpm SHA-256: 9f1c7c903961903b1bb95a970951f1c770d1392e1091e7f47cb20be4fe831618 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 SRPM grafana-pcp-5.1.1-17.el9_8.src.rpm SHA-256: 856c8dc3196ff776060222f24c179f9d34bf10e99a277622802f324c02946e79 ppc64le grafana-pcp-5.1.1-17.el9_8.ppc64le.rpm SHA-256: e7b692c8d0e729aea0f7db93470de56926b542bec23a75e7f3c8ffdb36327ed4 grafana-pcp-debuginfo-5.1.1-17.el9_8.ppc64le.rpm SHA-256: cfc2e1f0da6ecbdcc878fb844b631d3c58d97a6b1603bf59d03605c70e8b4c8c grafana-pcp-debugsource-5.1.1-17.el9_8.ppc64le.rpm SHA-256: d1965986151e0ce76717ee6bc15c99b5fdadcc625b30b37574da410e6d4c4f78 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 SRPM grafana-pcp-5.1.1-17.el9_8.src.rpm SHA-256: 856c8dc3196ff776060222f24c179f9d34bf10e99a277622802f324c02946e79 x86_64 grafana-pcp-5.1.1-17.el9_8.x86_64.rpm SHA-256: 60fb49276ab4869b1bf9789d6878b8c5e449cdd0391fb36647d3fff6c8923a24 grafana-pcp-debuginfo-5.1.1-17.el9_8.x86_64.rpm SHA-256: 00f9f5867e820e15c1fc13bee6e7c01b7d08290110908682ac8852e8c08aa0c7 grafana-pcp-debugsource-5.1.1-17.el9_8.x86_64.rpm SHA-256: 787d81cb2e9b81f69892adca81b58a95bbce204f40c0e0ce455de319f819576d Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 SRPM grafana-pcp-5.1.1-17.el9_8.src.rpm SHA-256: 856c8dc3196ff776060222f24c179f9d34bf10e99a277622802f324c02946e79 aarch64 grafana-pcp-5.1.1-17.el9_8.aarch64.rpm SHA-256: c39cb22b6ec086ae88d10c66863cb71fefe0b477dc69b4a816d2d4af769f2c5c grafana-pcp-debuginfo-5.1.1-17.el9_8.aarch64.rpm SHA-256: 2260bbb2f57e304a828f70970df7308365b83ebff7b6eade8e9104dae4da5739 grafana-pcp-debugsource-5.1.1-17.el9_8.aarch64.rpm SHA-256: 9f1c7c903961903b1bb95a970951f1c770d1392e1091e7f47cb20be4fe831618 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 SRPM grafana-pcp-5.1.1-17.el9_8.src.rpm SHA-256: 856c8dc3196ff776060222f24c179f9d34bf10e99a277622802f324c02946e79 s390x grafana-pcp-5.1.1-17.el9_8.s390x.rpm SHA-256: cb26eb89cee4761a376ab6d800c152c7491b819162f3380f86514ec147560061 grafana-pcp-debuginfo-5.1.1-17.el9_8.s390x.rpm SHA-256: fba3fea3f247725a7b3fcbc20c004cbf60780c47f2a22e9c4ddb4687a642b69a grafana-pcp-debugsource-5.1.1-17.el9_8.s390x.rpm SHA-256: 41501af92f35f20e282c463b92ee2afd2c366160b5760e8271567e77adc22f80 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 SRPM grafana-pcp-5.1.1-17.el9_8.src.rpm SHA-256: 856c8dc3196ff776060222f24c179f9d34bf10e99a277622802f324c02946e79 x86_64 grafana-pcp-5.1.1-17.el9_8.x86_64.rpm SHA-256: 60fb49276ab4869b1bf9789d6878b8c5e449cdd0391fb36647d3fff6c8923a24 grafana-pcp-debuginfo-5.1.1-17.el9_8.x86_64.rpm SHA-256: 00f9f5867e820e15c1fc13bee6e7c01b7d08290110908682ac8852e8c08aa0c7 grafana-pcp-debugsource-5.1.1-17.el9_8.x86_64.rpm SHA-256: 787d81cb2e9b81f69892adca81b58a95bbce204f40c0e0ce455de319f819576d Red Hat Enterprise Li
A critical privilege escalation vulnerability (CVE-2026-39821, CVSS 9.6) in the `golang.org/x/net/idna` library stems from incorrect Punycode label processing. The vulnerability affects the `grafana-pcp` plugin on RHEL 9, as it incorporates a vulnerable version of the Go library where `net` packages prior to version 0.55.0 are affected. The fix is applied by updating the `grafana-pcp` package via the Red Hat advisory, which addresses the underlying library flaw.