Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:56143: Important: grafana-pcp security update

A critical vulnerability (CVE-2026-39821, CVSS 9.6) in the `golang.org/x/net/idna` library allows privilege escalation via incorrect Punycode label processing, which is utilized by the grafana-pcp plugin. The flaw affects golang net library versions prior to 0.55.0. The fix is provided by updating the grafana-pcp package to version 5.3.0-1.el10_0 for Red Hat Enterprise Linux 10.0 Extended Update Support.
Read Full Article →

Red Hat Product Errata RHSA-2026:56143 - Security Advisory Issued: 2026-08-18 Updated: 2026-08-18 RHSA-2026:56143 - Security Advisory Overview Updated Packages Synopsis Important: grafana-pcp security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for grafana-pcp is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards. Security Fix(es): golang.org/x/net/idna: golang: net/ http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Fixes BZ - 2480756 - CVE-2026-39821 golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing CVEs CVE-2026-39821 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM grafana-pcp-5.3.0-1.el10_0.src.rpm SHA-256: 875e9e66b0041cef430800db2c29ded0bc6cc8b94987b137493b8e5ad6663370 x86_64 grafana-pcp-5.3.0-1.el10_0.x86_64.rpm SHA-256: 8f2aca703bde6327c432f758003ce652229feda80c5f0b2a2bae1952a876078e grafana-pcp-debuginfo-5.3.0-1.el10_0.x86_64.rpm SHA-256: a20a50ebbd66f57b21cbc66c522f9ea0de9e36ae47f7b495cc675befb79ad13a grafana-pcp-debugsource-5.3.0-1.el10_0.x86_64.rpm SHA-256: c9305eb36173ef5027138ca128c759c2a421537b4484241099618e2b7ef85869 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 SRPM grafana-pcp-5.3.0-1.el10_0.src.rpm SHA-256: 875e9e66b0041cef430800db2c29ded0bc6cc8b94987b137493b8e5ad6663370 s390x grafana-pcp-5.3.0-1.el10_0.s390x.rpm SHA-256: 5e1e4511f064be016736d23e5adc1d7257b2653fe5271cbd39ef7dabbc77a5bb grafana-pcp-debuginfo-5.3.0-1.el10_0.s390x.rpm SHA-256: bf20f814d8c761d059a28cfe183c1405960635e50ed91b3ce746533285d3905c grafana-pcp-debugsource-5.3.0-1.el10_0.s390x.rpm SHA-256: 29da0ac6ecc6f26daea5389392ac66551e8dd8b9ae6eda850e64c1b3668fbdea Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 SRPM grafana-pcp-5.3.0-1.el10_0.src.rpm SHA-256: 875e9e66b0041cef430800db2c29ded0bc6cc8b94987b137493b8e5ad6663370 ppc64le grafana-pcp-5.3.0-1.el10_0.ppc64le.rpm SHA-256: cc4d967649194a2f739b9e8e0bde9766b7bc0edab1f7f21edb17fffd776e1f86 grafana-pcp-debuginfo-5.3.0-1.el10_0.ppc64le.rpm SHA-256: 244772fb8a0364945a74f2d5265ac1317793d7b7ab9ff8c86e6a15c5dad8a30b grafana-pcp-debugsource-5.3.0-1.el10_0.ppc64le.rpm SHA-256: d4488d157727efac24ed45ffc39cab4e4215c6ab2c05846eb14a5f084bc1a330 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 SRPM grafana-pcp-5.3.0-1.el10_0.src.rpm SHA-256: 875e9e66b0041cef430800db2c29ded0bc6cc8b94987b137493b8e5ad6663370 aarch64 grafana-pcp-5.3.0-1.el10_0.aarch64.rpm SHA-256: 85122b2834fd4c76f943b1e34230093cbe96457fc767c5299a13bbc8c7d94309 grafana-pcp-debuginfo-5.3.0-1.el10_0.aarch64.rpm SHA-256: fc36827dc1d585c28ef36ed3542f144d368b32745261bd1313bee6508fcb7362 grafana-pcp-debugsource-5.3.0-1.el10_0.aarch64.rpm SHA-256: d8fc95a988be55b970d1d44fb49200d3f2645bec95e9246c27bf1a589a29b259 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 SRPM grafana-pcp-5.3.0-1.el10_0.src.rpm SHA-256: 875e9e66b0041cef430800db2c29ded0bc6cc8b94987b137493b8e5ad6663370 aarch64 grafana-pcp-5.3.0-1.el10_0.aarch64.rpm SHA-256: 85122b2834fd4c76f943b1e34230093cbe96457fc767c5299a13bbc8c7d94309 grafana-pcp-debuginfo-5.3.0-1.el10_0.aarch64.rpm SHA-256: fc36827dc1d585c28ef36ed3542f144d368b32745261bd1313bee6508fcb7362 grafana-pcp-debugsource-5.3.0-1.el10_0.aarch64.rpm SHA-256: d8fc95a988be55b970d1d44fb49200d3f2645bec95e9246c27bf1a589a29b259 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 SRPM grafana-pcp-5.3.0-1.el10_0.src.rpm SHA-256: 875e9e66b0041cef430800db2c29ded0bc6cc8b94987b137493b8e5ad6663370 s390x grafana-pcp-5.3.0-1.el10_0.s390x.rpm SHA-256: 5e1e4511f064be016736d23e5adc1d7257b2653fe5271cbd39ef7dabbc77a5bb grafana-pcp-debuginfo-5.3.0-1.el10_0.s390x.rpm SHA-256: bf20f814d8c761d059a28cfe183c1405960635e50ed91b3ce746533285d3905c grafana-pcp-debugsource-5.3.0-1.el10_0.s390x.rpm SHA-256: 29da0ac6ecc6f26daea5389392ac66551e8dd8b9ae6eda850e64c1b3668fbdea Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 SRPM grafana-pcp-5.3.0-1.el10_0.src.rpm SHA-256: 875e9e66b0041cef430800db2c29ded0bc6cc8b94987b137493b8e5ad6663370 ppc64le grafana-pcp-5.3.0-1.el10_0.ppc64le.rpm SHA-256: cc4d967649194a2f739b9e8e0bde9766b7bc0edab1f7f21edb17fffd776e1f86 grafana-pcp-debuginfo-5.3.0-1.el10_0.ppc64le.rpm SHA-256: 244772fb8a0364945a74f2d5265ac1317793d7b7ab9ff8c86e6a15c5dad8a30b grafana-pcp-debugsource-5.3.0-1.el10_0.ppc64le.rpm SHA-256: d4488d157727efac24ed45ffc39cab4e4215c6ab2c05846eb14a5f084bc1a330 Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 SRPM grafana-pcp-5.3.0-1.el10_0.src.rpm SHA-256: 875e9e66b0041cef430800db2c29ded0bc6cc8b94987b137493b8e5ad6663370 x86_64 grafana-pcp-5.3.0-1.el10_0.x86_64.rpm SHA-256: 8f2aca703bde6327c432f758003ce652229feda80c5f0b2a2bae1952a876078e grafana-pcp-debuginfo-5.3.0-1.el10_0.x86_64.rpm SHA-256: a20a50ebbd66f57b21cbc66c522f9ea0de9e36ae47f7b495cc675befb79ad13a grafana-pcp-debugsource-5.3.0-1.el10_0.x86_64.rpm SHA-256: c9305eb36173ef5027138ca128c759c2a421537b4484241099618e2b7ef85869 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article