RHSA-2024:1502: Important: grafana-pcp security update
grafana-pcp is an open source Grafana plugin for PCP.Security Fix(es): grafana-pcp: golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/grafana-pcpto a version that resolves this vulnerability.Fixed in 5.1.1-2.el9_3 - Upgrade
Upgrade
redhat/grafana-pcp-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-2.el9_3 - Upgrade
Upgrade
redhat/grafana-pcp-debugsourceto a version that resolves this vulnerability.Fixed in 5.1.1-2.el9_3 - Upgrade
Upgrade
redhat/grafana-pcpto a version that resolves this vulnerability.Fixed in 5.1.1-2.el9_3.aa - Upgrade
Upgrade
redhat/grafana-pcp-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-2.el9_3.aa - Upgrade
Upgrade
redhat/grafana-pcp-debugsourceto a version that resolves this vulnerability.Fixed in 5.1.1-2.el9_3.aa
Event History
Frequently Asked Questions
What security vulnerabilities are addressed in RHSA-2024:1502?
RHSA-2024:1502 addresses memory leaks in the grafana-pcp plugin due to issues in RSA payload encryption and decryption as identified by CVE-2024-1394.
What is the severity of RHSA-2024:1502?
The severity of RHSA-2024:1502 is classified as important.
How do I fix RHSA-2024:1502?
To fix RHSA-2024:1502, update grafana-pcp to version 5.1.1-2.el9_3 or later.
Which versions of grafana-pcp are affected by RHSA-2024:1502?
Versions of grafana-pcp prior to 5.1.1-2.el9_3 are affected by RHSA-2024:1502.
Is there a specific package version required for the fix in RHSA-2024:1502?
Yes, the specific package version required for the fix in RHSA-2024:1502 is 5.1.1-2.el9_3.