RHSA-2026:33731: Moderate: rrdtool security update
Moderate: rrdtool security update
Other sources
The round robin database (RRD) system stores and displays time-series data, such as network bandwidth, machine-room temperature, and server load average. RRDtool is a high performance data logging and graphing utility, which can be easily integrated with shell scripts, or used to create applications using its Perl, Python, Ruby, Lua, Tcl, and PHP bindings. The data is stored in a compact manner that does not expand over time, and RRDtool provides the user with useful graphs by processing the data to enforce a certain data density.Security Fix(es): rrdtool: Stack buffer overflow in rrdcached handlerequestcreate() allows local privilege escalation via unbounded DS/RRA arguments (CVE-2026-43958) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/rrdtoolto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2 - Upgrade
Upgrade
redhat/python3-rrdtool-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2 - Upgrade
Upgrade
redhat/rrdtool-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2 - Upgrade
Upgrade
redhat/rrdtool-debugsourceto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2 - Upgrade
Upgrade
redhat/rrdtool-lua-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2 - Upgrade
Upgrade
redhat/rrdtool-perlto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2 - Upgrade
Upgrade
redhat/rrdtool-perl-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2 - Upgrade
Upgrade
redhat/rrdtool-ruby-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2 - Upgrade
Upgrade
redhat/rrdtool-tcl-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2 - Upgrade
Upgrade
redhat/python3-rrdtool-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2.aa - Upgrade
Upgrade
redhat/rrdtoolto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2.aa - Upgrade
Upgrade
redhat/rrdtool-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2.aa - Upgrade
Upgrade
redhat/rrdtool-debugsourceto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2.aa - Upgrade
Upgrade
redhat/rrdtool-lua-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2.aa - Upgrade
Upgrade
redhat/rrdtool-perlto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2.aa - Upgrade
Upgrade
redhat/rrdtool-perl-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2.aa - Upgrade
Upgrade
redhat/rrdtool-ruby-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2.aa - Upgrade
Upgrade
redhat/rrdtool-tcl-debuginfoto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2.aa - Upgrade
Upgrade
redhat/python3-rrdtoolto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2 - Upgrade
Upgrade
redhat/rrdtool-develto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2 - Upgrade
Upgrade
redhat/rrdtool-docto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2 - Upgrade
Upgrade
redhat/rrdtool-luato a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2 - Upgrade
Upgrade
redhat/rrdtool-rubyto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2 - Upgrade
Upgrade
redhat/rrdtool-tclto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2 - Upgrade
Upgrade
redhat/python3-rrdtoolto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2.aa - Upgrade
Upgrade
redhat/rrdtool-develto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2.aa - Upgrade
Upgrade
redhat/rrdtool-docto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2.aa - Upgrade
Upgrade
redhat/rrdtool-luato a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2.aa - Upgrade
Upgrade
redhat/rrdtool-rubyto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2.aa - Upgrade
Upgrade
redhat/rrdtool-tclto a version that resolves this vulnerability.Fixed in 1.8.0-21.el10_2.aa - Upgrade
Upgrade
rrdtoolto a version that resolves this vulnerability.Patch CVE-2026-43958 - Compensating control
If possible before applying the update, restrict local access to the rrdcached service so only trusted users/hosts can reach rrdcached, reducing exposure to the local privilege escalation described for handle_request_create().
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:33731?
The severity of RHSA-2026:33731 is medium, with a score of 4.
What is the description of RHSA-2026:33731?
RHSA-2026:33731 is a security update for RRDtool, which is used for storing and displaying time-series data.
How do I fix RHSA-2026:33731?
To fix RHSA-2026:33731, you should update the affected packages related to RRDtool in your system.
What vulnerability does RHSA-2026:33731 address?
RHSA-2026:33731 addresses a buffer overflow vulnerability in RRDtool.
What software is affected by RHSA-2026:33731?
Affected software includes redhat/rrdtool and various debug information packages related to RRDtool.