RHSA-2026:56143: Important: grafana-pcp security update
Important: grafana-pcp security update
Other sources
The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards.Security Fix(es): golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/grafana-pcpto a version that resolves this vulnerability.Fixed in 5.3.0-1.el10_0 - Upgrade
Upgrade
redhat/grafana-pcp-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.0-1.el10_0 - Upgrade
Upgrade
redhat/grafana-pcp-debugsourceto a version that resolves this vulnerability.Fixed in 5.3.0-1.el10_0 - Upgrade
Upgrade
redhat/grafana-pcpto a version that resolves this vulnerability.Fixed in 5.3.0-1.el10_0.aa - Upgrade
Upgrade
redhat/grafana-pcp-debuginfoto a version that resolves this vulnerability.Fixed in 5.3.0-1.el10_0.aa - Upgrade
Upgrade
redhat/grafana-pcp-debugsourceto a version that resolves this vulnerability.Fixed in 5.3.0-1.el10_0.aa - Upgrade
Upgrade
grafana-pcp (Grafana plugin for Performance Co-Pilot)to a version that resolves this vulnerability.Patch CVE-2026-39821
Event History
Frequently Asked Questions
Which deployed systems and packages are covered by this update?
The advisory applies to grafana-pcp and its debuginfo and debugsource packages on the listed Red Hat Enterprise Linux architectures: x86_64, ARM 64, Power little endian, and IBM z Systems, including the specified extended support offering for Power little endian.
What is known about exploitation conditions and mitigation if the update cannot be installed immediately?
The reported issue is CVE-2026-39821 in golang.org/x/net/idna, involving incorrect Punycode label processing in Go net/http that can lead to privilege escalation. The provided advisory data does not specify the required attacker access, affected configuration, or a workaround.