Red Hat Product Errata RHSA-2026:35828 - Security Advisory Issued: 2026-07-06 Updated: 2026-07-06 RHSA-2026:35828 - Security Advisory Overview Updated Packages Synopsis Important: grafana security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for grafana is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB. Security Fix(es): golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2480756 - CVE-2026-39821 golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVEs CVE-2026-39821 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM grafana-10.2.6-23.el9_8.src.rpm SHA-256: b7f55169c623f181cb09983dbd652b02a17432c4538264083fbb8249c8864973 x86_64 grafana-10.2.6-23.el9_8.x86_64.rpm SHA-256: 62c12244f45d49474c82edcd52eaa96aba906aede63a46cb019ab3c314e9c930 grafana-debuginfo-10.2.6-23.el9_8.x86_64.rpm SHA-256: 17bcc643d20a32bccb5dd3c014b72800a4dd90b48b7d56e328598f1e8a619993 grafana-debugsource-10.2.6-23.el9_8.x86_64.rpm SHA-256: 0593f2f0def87f57c082210f1d475d81a29a3c13557215dd5649ec492c6cbb67 grafana-selinux-10.2.6-23.el9_8.x86_64.rpm SHA-256: 5cbdbce71d599efcd4a116700daba9886c575bfa4b4b97e04b37cbff0951f414 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM grafana-10.2.6-23.el9_8.src.rpm SHA-256: b7f55169c623f181cb09983dbd652b02a17432c4538264083fbb8249c8864973 x86_64 grafana-10.2.6-23.el9_8.x86_64.rpm SHA-256: 62c12244f45d49474c82edcd52eaa96aba906aede63a46cb019ab3c314e9c930 grafana-debuginfo-10.2.6-23.el9_8.x86_64.rpm SHA-256: 17bcc643d20a32bccb5dd3c014b72800a4dd90b48b7d56e328598f1e8a619993 grafana-debugsource-10.2.6-23.el9_8.x86_64.rpm SHA-256: 0593f2f0def87f57c082210f1d475d81a29a3c13557215dd5649ec492c6cbb67 grafana-selinux-10.2.6-23.el9_8.x86_64.rpm SHA-256: 5cbdbce71d599efcd4a116700daba9886c575bfa4b4b97e04b37cbff0951f414 Red Hat Enterprise Linux for IBM z Systems 9 SRPM grafana-10.2.6-23.el9_8.src.rpm SHA-256: b7f55169c623f181cb09983dbd652b02a17432c4538264083fbb8249c8864973 s390x grafana-10.2.6-23.el9_8.s390x.rpm SHA-256: 5fb6a957ed4395ca1804c79f61988d8ac223208d5b50a2102a5a39c3fc56d3a7 grafana-debuginfo-10.2.6-23.el9_8.s390x.rpm SHA-256: d6f9026c5b3c31e1ca7c24fb3727eb42a271f68f0fb306a06273f4e858a1230d grafana-debugsource-10.2.6-23.el9_8.s390x.rpm SHA-256: 015de63591776967951fc98c8b092796f8da2afad5a53144811e2cb513d22974 grafana-selinux-10.2.6-23.el9_8.s390x.rpm SHA-256: 1935c1fc2314b4667d3d90f230e0e86796983e21e9a1eb3e912645e7fd0e8be7 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 SRPM grafana-10.2.6-23.el9_8.src.rpm SHA-256: b7f55169c623f181cb09983dbd652b02a17432c4538264083fbb8249c8864973 s390x grafana-10.2.6-23.el9_8.s390x.rpm SHA-256: 5fb6a957ed4395ca1804c79f61988d8ac223208d5b50a2102a5a39c3fc56d3a7 grafana-debuginfo-10.2.6-23.el9_8.s390x.rpm SHA-256: d6f9026c5b3c31e1ca7c24fb3727eb42a271f68f0fb306a06273f4e858a1230d grafana-debugsource-10.2.6-23.el9_8.s390x.rpm SHA-256: 015de63591776967951fc98c8b092796f8da2afad5a53144811e2cb513d22974 grafana-selinux-10.2.6-23.el9_8.s390x.rpm SHA-256: 1935c1fc2314b4667d3d90f230e0e86796983e21e9a1eb3e912645e7fd0e8be7 Red Hat Enterprise Linux for Power, little endian 9 SRPM grafana-10.2.6-23.el9_8.src.rpm SHA-256: b7f55169c623f181cb09983dbd652b02a17432c4538264083fbb8249c8864973 ppc64le grafana-10.2.6-23.el9_8.ppc64le.rpm SHA-256: 471048dc628693064e2eef61fd81dfb9fce86fe89292d6b5c731347e539e70f2 grafana-debuginfo-10.2.6-23.el9_8.ppc64le.rpm SHA-256: d8a9d64bc00fa774fa7f29442997d5aac3441a3b4083b7b908577a5bf45f9c8c grafana-debugsource-10.2.6-23.el9_8.ppc64le.rpm SHA-256: 8ad9b3abd292a95b1b1facd20bf852b388b817557a308f645b744426f263bcdb grafana-selinux-10.2.6-23.el9_8.ppc64le.rpm SHA-256: a4a204b063e84939a00fae7efcd2ae1812d59647471d2070e9d3cfc2960eebf7 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 SRPM grafana-10.2.6-23.el9_8.src.rpm SHA-256: b7f55169c623f181cb09983dbd652b02a17432c4538264083fbb8249c8864973 ppc64le grafana-10.2.6-23.el9_8.ppc64le.rpm SHA-256: 471048dc628693064e2eef61fd81dfb9fce86fe89292d6b5c731347e539e70f2 grafana-debuginfo-10.2.6-23.el9_8.ppc64le.rpm SHA-256: d8a9d64bc00fa774fa7f29442997d5aac3441a3b4083b7b908577a5bf45f9c8c grafana-debugsource-10.2.6-23.el9_8.ppc64le.rpm SHA-256: 8ad9b3abd292a95b1b1facd20bf852b388b817557a308f645b744426f263bcdb grafana-selinux-10.2.6-23.el9_8.ppc64le.rpm SHA-256: a4a204b063e84939a00fae7efcd2ae1812d59647471d2070e9d3cfc2960eebf7 Red Hat Enterprise Linux for ARM 64 9 SRPM grafana-10.2.6-23.el9_8.src.rpm SHA-256: b7f55169c623f181cb09983dbd652b02a17432c4538264083fbb8249c8864973 aarch64 grafana-10.2.6-23.el9_8.aarch64.rpm SHA-256: 9bdcdf8693ae5b04f72033634991c528bc7396dd4146a35119173f7cd02ab6ac grafana-debuginfo-10.2.6-23.el9_8.aarch64.rpm SHA-256: c2a065e7e30b6561ff90a6b6d35a275bbd8bfe97965caa86591fe63be01e4cdd grafana-debugsource-10.2.6-23.el9_8.aarch64.rpm SHA-256: 02794ef599d9436a6253369b6e20ad28c4b37435ea0c6071145afa54f30e3f55 grafana-selinux-10.2.6-23.el9_8.aarch64.rpm SHA-256: 033c72578f0d59b777cae0a550bd002e8d96d0a1795f1d3e583d06dd9b902c5e Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 SRPM grafana-10.2.6-23.el9_8.src.rpm SHA-256: b7f55169c623f181cb09983dbd652b02a17432c4538264083fbb8249c8864973 aarch64 grafana-10.2.6-23.el9_8.aarch64.rpm SHA-256: 9bdcdf8693ae5b04f72033634991c528bc7396dd4146a35119173f7cd02ab6ac grafana-debuginfo-10.2.6-23.el9_8.aarch64.rpm SHA-256: c2a065e7e30b6561ff90a6b6d35a275bbd8bfe97965caa86591fe63be01e4cdd grafana-debugsource-10.2.6-23.el9_8.aarch64.rpm SHA-256: 02794ef599d9436a6253369b6e20ad28c4b37435ea0c6071145afa54f30e3f55 grafana-selinux-10.2.6-23.el9_8.aarch64.rpm SHA-256: 033c72578f0d59b777cae0a550bd002e8d96d0a1795f1d3e583d06dd9b902c5e Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 SRPM grafana-10.2.6-23.el9_8.src.rpm SHA-256: b7f55169c623f181cb09983dbd652b02a17432c4538264083fbb8249c8864973 ppc64le grafana-10.2.6-23.el9_8.ppc64le.rpm SHA-256: 471048dc628693064e2eef61fd81dfb9fce86fe89292d6b5c731347e539e70f2 grafana-debuginfo-10.2.6-23.el9_8.ppc64le.rpm SHA-256: d8a9d64bc00fa774fa7f29442997d5aac3441a3b4083b7b908577a5bf45f9c8c grafana-debugsource-10.2.6-23.el9_8.ppc64le.rpm SHA-256: 8ad9b3abd292a95b1b1facd20bf852b388b817557a308f645b744426f263bcdb grafana-selinux-10.2.6-23.el9_8.ppc64le.rpm SHA-256: a4a204b063e84939a00fae7efcd2ae1812d59647471d2070e9d3cfc2960eebf7 Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 SRPM grafana-10.2.6-23.el9_8.src.rpm SHA-256: b7f55169c623f181cb09983dbd652b02a17432c4538264083fbb8249c8864973 x86_64 grafana-10.2.6-23.el9_8.x86_64.rpm SHA-256: 62c12244f45d49474c82edcd52eaa96aba906aede63a46cb019ab3c314e9c930 grafana-debuginfo-10.2.6-23.el9_8.x86_64.rpm SHA-256: 17bcc643d20a32bccb5dd3c014b72800a4dd90b48b7d56e328598f1e8a619993 grafana-debugsource-10.2.6-23.el9_8.x86_64.rpm SHA-256: 0593f2f0def87f57c082210f1d475d81a29a3c13557215dd5649ec492c6cbb67 grafana-selinux-10.2.6-23.el9_8.x86_64.rpm SHA-256: 5cbdbce71d599efcd4a116700daba9886c575bfa4b4b97e04b37cbff0951f414 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 SRPM grafana-10.2.6-23.el9_8.src.rpm SHA-256: b7f55169c623f181cb09983dbd652b02a17432c4538264083fbb8249c8864973 aarch64 grafana-10.2.6-23.el9_8.aarch64.rpm SHA-256: 9bdcdf8693ae5b04f72033634991c528bc7396dd4146a35119173f7cd02ab6ac grafana-debuginfo-10.2.6-23.el9_8.aarch64.rpm SHA-256: c2a065e7e30b6561ff90a6b6d35a275bbd8bfe97965caa86591fe63be01e4cdd grafana-debugsource-10.2.6-23.el9_8.aarch64.rpm SHA-256: 02794ef599d9436a6253369b6e20ad28c4b37435ea0c6071145afa54f30e3f55 grafana-selinux-10.2.6-23.el9_8.aarch64.rpm SHA-256: 033c72578f0d59b777cae0a550bd002e8d96d0a1795f1d3e583d06dd9b902c5e Red Hat Enterprise Linux for IBM z Systems - 4
A critical privilege escalation vulnerability (CVE-2026-39821, CVSS 9.6) exists in the `golang.org/x/net/idna` library due to incorrect Punycode label processing. The flaw affects Grafana packages on Red Hat Enterprise Linux 9 that incorporate a vulnerable version of the Go library, specifically any version of the `golang.org/x/net` module prior to version 0.55.0. The fix requires updating the underlying Go component to version 0.55.0, which is included in the patched Grafana packages provided by Red Hat.