- What: Security update for Grafana-PCP in Red Hat Enterprise Linux
- Impact: Systems using Grafana-PCP may be vulnerable if not updated
Red Hat Product Errata RHSA-2026:63124 - Security Advisory Issued: 2026-09-03 Updated: 2026-09-03 RHSA-2026:63124 - Security Advisory Overview Updated Packages Synopsis Important: grafana-pcp security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for grafana-pcp is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards. Security Fix(es): mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) net/ http: golang: Go net/ http: Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) html/template: golang: Go html/template: Cross-Site Scripting via pathological input (CVE-2026-56858) crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2484204 - CVE-2026-42504 mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header BZ - 2515815 - CVE-2026-33818 encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal BZ - 2515820 - CVE-2026-56860 net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution BZ - 2515827 - CVE-2026-56853 net/http: golang: Go net/http: Unencrypted HTTP/2 connections vulnerable to Denial of Service BZ - 2515838 - CVE-2026-56858 html/template: golang: Go html/template: Cross-Site Scripting via pathological input BZ - 2515839 - CVE-2026-56862 crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages CVEs CVE-2026-33818 CVE-2026-42504 CVE-2026-56853 CVE-2026-56858 CVE-2026-56860 CVE-2026-56862 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM grafana-pcp-5.1.1-18.el8_10.src.rpm SHA-256: 9d5366eaa5150845ed2b239c5b71986d70a52c8940a9db3402c97c8298274d67 x86_64 grafana-pcp-5.1.1-18.el8_10.x86_64.rpm SHA-256: 0d0a8d4dc8bf596b18f3f70472396183339b6327239e85b1c5d8da6920c9eec0 grafana-pcp-debuginfo-5.1.1-18.el8_10.x86_64.rpm SHA-256: 006325758d794431df77ed7577b4419609ca663b8890f27b5c886c200fce29d9 grafana-pcp-debugsource-5.1.1-18.el8_10.x86_64.rpm SHA-256: 4dc666cea3a5288cceed6c8ad0384ee713de256e88b3658be7d2812124672c80 Red Hat Enterprise Linux for IBM z Systems 8 SRPM grafana-pcp-5.1.1-18.el8_10.src.rpm SHA-256: 9d5366eaa5150845ed2b239c5b71986d70a52c8940a9db3402c97c8298274d67 s390x grafana-pcp-5.1.1-18.el8_10.s390x.rpm SHA-256: d1b0e4d60b63be9d820ef4e3691c61abcf2e2ad339fa351f0714d160295c646e grafana-pcp-debuginfo-5.1.1-18.el8_10.s390x.rpm SHA-256: a38991755ec37bd3f5401aa7dedfe2ab53f367d894159d642063f8bd7b34999a grafana-pcp-debugsource-5.1.1-18.el8_10.s390x.rpm SHA-256: a59bde26f8adab1d4469f9eea2bb7fe25bc3febab8745a6f5e8ddddfb0cf0a38 Red Hat Enterprise Linux for Power, little endian 8 SRPM grafana-pcp-5.1.1-18.el8_10.src.rpm SHA-256: 9d5366eaa5150845ed2b239c5b71986d70a52c8940a9db3402c97c8298274d67 ppc64le grafana-pcp-5.1.1-18.el8_10.ppc64le.rpm SHA-256: 2ec5e5ab9a682a25a56f2bd006fb33ce7ffe872592ee7420877c17f7d64128cd grafana-pcp-debuginfo-5.1.1-18.el8_10.ppc64le.rpm SHA-256: 60149215078e794fe8a0deb2a0998323a1cf28708342b9ff27b7d4a66fc24878 grafana-pcp-debugsource-5.1.1-18.el8_10.ppc64le.rpm SHA-256: c113736eb99d4ce5beb4a6e0b84a5a588507c550c48f902b6a4994127195d5c4 Red Hat Enterprise Linux for ARM 64 8 SRPM grafana-pcp-5.1.1-18.el8_10.src.rpm SHA-256: 9d5366eaa5150845ed2b239c5b71986d70a52c8940a9db3402c97c8298274d67 aarch64 grafana-pcp-5.1.1-18.el8_10.aarch64.rpm SHA-256: 241b7c57cd05007f0dfc2c01b2b7db1dd79c16b34d97d8b7972f7bad2e68a1a9 grafana-pcp-debuginfo-5.1.1-18.el8_10.aarch64.rpm SHA-256: ead28ade25d21258a2b425bcaef1710153c064c43340ef50d6153246768e6f3a grafana-pcp-debugsource-5.1.1-18.el8_10.aarch64.rpm SHA-256: 84d7585fb0488cd1d56e83118f0d4d3aac9f79d5033593ede1bbf73c3888dc0a Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 SRPM grafana-pcp-5.1.1-18.el8_10.src.rpm SHA-256: 9d5366eaa5150845ed2b239c5b71986d70a52c8940a9db3402c97c8298274d67 x86_64 grafana-pcp-5.1.1-18.el8_10.x86_64.rpm SHA-256: 0d0a8d4dc8bf596b18f3f70472396183339b6327239e85b1c5d8da6920c9eec0 grafana-pcp-debuginfo-5.1.1-18.el8_10.x86_64.rpm SHA-256: 006325758d794431df77ed7577b4419609ca663b8890f27b5c886c200fce29d9 grafana-pcp-debugsource-5.1.1-18.el8_10.x86_64.rpm SHA-256: 4dc666cea3a5288cceed6c8ad0384ee713de256e88b3658be7d2812124672c80 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 SRPM grafana-pcp-5.1.1-18.el8_10.src.rpm SHA-256: 9d5366eaa5150845ed2b239c5b71986d70a52c8940a9db3402c97c8298274d67 aarch64 grafana-pcp-5.1.1-18.el8_10.aarch64.rpm SHA-256: 241b7c57cd05007f0dfc2c01b2b7db1dd79c16b34d97d8b7972f7bad2e68a1a9 grafana-pcp-debuginfo-5.1.1-18.el8_10.aarch64.rpm SHA-256: ead28ade25d21258a2b425bcaef1710153c064c43340ef50d6153246768e6f3a grafana-pcp-debugsource-5.1.1-18.el8_10.aarch64.rpm SHA-256: 84d7585fb0488cd1d56e83118f0d4d3aac9f79d5033593ede1bbf73c3888dc0a Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 SRPM grafana-pcp-5.1.1-18.el8_10.src.rpm SHA-256: 9d5366eaa5150845ed2b239c5b71986d70a52c8940a9db3402c97c8298274d67 ppc64le grafana-pcp-5.1.1-18.el8_10.ppc64le.rpm SHA-256: 2ec5e5ab9a682a25a56f2bd006fb33ce7ffe872592ee7420877c17f7d64128cd grafana-pcp-debuginfo-5.1.1-18.el8_10.ppc64le.rpm SHA-256: 60149215078e794fe8a0deb2a0998323a1cf28708342b9ff27b7d4a66fc24878 grafana-pcp-debugsource-5.1.1-18.el8_10.ppc64le.rpm SHA-256: c113736eb99d4ce5beb4a6e0b84a5a588507c550c48f902b6a4994127195d5c4 Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 SRPM grafana-pcp-5.1.1-18.el8_10.src.rpm SHA-256: 9d5366eaa5150845ed2b239c5b71986d70a52c8940a9db3402c97c8298274d67 s390x grafana-pcp-5.1.1-18.el8_10.s390x.rpm SHA-256: d1b0e4d60b63be9d820ef4e3691c61abcf2e2ad339fa351f0714d160295c646e grafana-pcp-debuginfo-5.1.1-18.el8_10.s390x.rpm SHA-256: a38991755ec37bd3f5401aa7dedfe2ab53f367d894159d642063f8bd7b34999a grafana-pcp-debugsource-5.1.1-18.el8_10.s390x.rpm SHA-256: a59bde26f8adab1d4469f9eea2bb7fe25bc3febab8745a6f5e8ddddfb0cf0a38 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .