Red Hat Product Errata RHSA-2026:35831 - Security Advisory Issued: 2026-07-06 Updated: 2026-07-06 RHSA-2026:35831 - Security Advisory Overview Updated Packages Synopsis Important: grafana-pcp security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for grafana-pcp is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards. Security Fix(es): golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2480756 - CVE-2026-39821 golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVEs CVE-2026-39821 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM grafana-pcp-5.1.1-16.el8_10.src.rpm SHA-256: b5fcad6f756839133c0a9acfe56a5405306b2edbd708b13e6e3f6d5c414eb28a x86_64 grafana-pcp-5.1.1-16.el8_10.x86_64.rpm SHA-256: e5e356a22262fd017687e11084b58d907ec83f528162df5e64f5b9afee74635a grafana-pcp-debuginfo-5.1.1-16.el8_10.x86_64.rpm SHA-256: d562a6bbbd129c92123c1f5d0e6822a23abcc7e7840c39dccbbf6de8c662d6f4 grafana-pcp-debugsource-5.1.1-16.el8_10.x86_64.rpm SHA-256: f9387b9684b95be42ab8473c9e0b549ef1b775f5243726c78c3eae295894d0a1 Red Hat Enterprise Linux for IBM z Systems 8 SRPM grafana-pcp-5.1.1-16.el8_10.src.rpm SHA-256: b5fcad6f756839133c0a9acfe56a5405306b2edbd708b13e6e3f6d5c414eb28a s390x grafana-pcp-5.1.1-16.el8_10.s390x.rpm SHA-256: 04902448faf0a9ad5c01e3501493dc7c436f4741c9e168bd947e3345dcab4ea3 grafana-pcp-debuginfo-5.1.1-16.el8_10.s390x.rpm SHA-256: 3639ce07f77b5ca43b680db18cef565b9888532e14478f86d8a7ed76e907396d grafana-pcp-debugsource-5.1.1-16.el8_10.s390x.rpm SHA-256: 5a9bc8dfa2b951a7682150c6662ae75304d8ad10af326d4d0f2c6ee89616f821 Red Hat Enterprise Linux for Power, little endian 8 SRPM grafana-pcp-5.1.1-16.el8_10.src.rpm SHA-256: b5fcad6f756839133c0a9acfe56a5405306b2edbd708b13e6e3f6d5c414eb28a ppc64le grafana-pcp-5.1.1-16.el8_10.ppc64le.rpm SHA-256: 2290eedd7bb618da64c4043068a200cc408105ca2db0a4c1f3d2188780e1b495 grafana-pcp-debuginfo-5.1.1-16.el8_10.ppc64le.rpm SHA-256: 805ea25aa39693d0fdf8c41e1e6471a33f47d28e4ca5e2a01e7b7b1a894341fa grafana-pcp-debugsource-5.1.1-16.el8_10.ppc64le.rpm SHA-256: 687d0425cdf4dba1ebe52bcca518ad3b8c7b1aff13cd437ca68900d9ef657807 Red Hat Enterprise Linux for ARM 64 8 SRPM grafana-pcp-5.1.1-16.el8_10.src.rpm SHA-256: b5fcad6f756839133c0a9acfe56a5405306b2edbd708b13e6e3f6d5c414eb28a aarch64 grafana-pcp-5.1.1-16.el8_10.aarch64.rpm SHA-256: ed0cd22f02dd69b40689e29680d88c329c8ff9b153947828b8ca9493d3e6b999 grafana-pcp-debuginfo-5.1.1-16.el8_10.aarch64.rpm SHA-256: f267d97b115147b7d4d8b19f12cdb520a71527c4021259e683a174ce011370e7 grafana-pcp-debugsource-5.1.1-16.el8_10.aarch64.rpm SHA-256: aefb20f1fef4cfe9b8c231c97d8b5e96587721e7efc8de9a7f4d38f85c8a1b3d Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 SRPM grafana-pcp-5.1.1-16.el8_10.src.rpm SHA-256: b5fcad6f756839133c0a9acfe56a5405306b2edbd708b13e6e3f6d5c414eb28a x86_64 grafana-pcp-5.1.1-16.el8_10.x86_64.rpm SHA-256: e5e356a22262fd017687e11084b58d907ec83f528162df5e64f5b9afee74635a grafana-pcp-debuginfo-5.1.1-16.el8_10.x86_64.rpm SHA-256: d562a6bbbd129c92123c1f5d0e6822a23abcc7e7840c39dccbbf6de8c662d6f4 grafana-pcp-debugsource-5.1.1-16.el8_10.x86_64.rpm SHA-256: f9387b9684b95be42ab8473c9e0b549ef1b775f5243726c78c3eae295894d0a1 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 SRPM grafana-pcp-5.1.1-16.el8_10.src.rpm SHA-256: b5fcad6f756839133c0a9acfe56a5405306b2edbd708b13e6e3f6d5c414eb28a aarch64 grafana-pcp-5.1.1-16.el8_10.aarch64.rpm SHA-256: ed0cd22f02dd69b40689e29680d88c329c8ff9b153947828b8ca9493d3e6b999 grafana-pcp-debuginfo-5.1.1-16.el8_10.aarch64.rpm SHA-256: f267d97b115147b7d4d8b19f12cdb520a71527c4021259e683a174ce011370e7 grafana-pcp-debugsource-5.1.1-16.el8_10.aarch64.rpm SHA-256: aefb20f1fef4cfe9b8c231c97d8b5e96587721e7efc8de9a7f4d38f85c8a1b3d Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 SRPM grafana-pcp-5.1.1-16.el8_10.src.rpm SHA-256: b5fcad6f756839133c0a9acfe56a5405306b2edbd708b13e6e3f6d5c414eb28a ppc64le grafana-pcp-5.1.1-16.el8_10.ppc64le.rpm SHA-256: 2290eedd7bb618da64c4043068a200cc408105ca2db0a4c1f3d2188780e1b495 grafana-pcp-debuginfo-5.1.1-16.el8_10.ppc64le.rpm SHA-256: 805ea25aa39693d0fdf8c41e1e6471a33f47d28e4ca5e2a01e7b7b1a894341fa grafana-pcp-debugsource-5.1.1-16.el8_10.ppc64le.rpm SHA-256: 687d0425cdf4dba1ebe52bcca518ad3b8c7b1aff13cd437ca68900d9ef657807 Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 SRPM grafana-pcp-5.1.1-16.el8_10.src.rpm SHA-256: b5fcad6f756839133c0a9acfe56a5405306b2edbd708b13e6e3f6d5c414eb28a s390x grafana-pcp-5.1.1-16.el8_10.s390x.rpm SHA-256: 04902448faf0a9ad5c01e3501493dc7c436f4741c9e168bd947e3345dcab4ea3 grafana-pcp-debuginfo-5.1.1-16.el8_10.s390x.rpm SHA-256: 3639ce07f77b5ca43b680db18cef565b9888532e14478f86d8a7ed76e907396d grafana-pcp-debugsource-5.1.1-16.el8_10.s390x.rpm SHA-256: 5a9bc8dfa2b951a7682150c6662ae75304d8ad10af326d4d0f2c6ee89616f821 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .
A critical privilege escalation vulnerability (CVE-2026-39821, CVSS 9.6) exists in the golang.org/x/net/idna library due to incorrect Punycode label processing. The flaw affects the grafana-pcp plugin on Red Hat Enterprise Linux 8, specifically where the underlying golang net library version is less than 0.55.0. The fix requires applying the Red Hat security update for grafana-pcp, which incorporates the patched library.