RHSA-2026:56223: Important: grafana-pcp security update
Important: grafana-pcp security update
Other sources
The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards.Security Fix(es): golang.org/x/net/idna: golang: net/http: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/grafana-pcpto a version that resolves this vulnerability.Fixed in 5.1.1-15.el9_6 - Upgrade
Upgrade
redhat/grafana-pcp-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-15.el9_6 - Upgrade
Upgrade
redhat/grafana-pcp-debugsourceto a version that resolves this vulnerability.Fixed in 5.1.1-15.el9_6 - Upgrade
Upgrade
redhat/grafana-pcpto a version that resolves this vulnerability.Fixed in 5.1.1-15.el9_6.aa - Upgrade
Upgrade
redhat/grafana-pcp-debuginfoto a version that resolves this vulnerability.Fixed in 5.1.1-15.el9_6.aa - Upgrade
Upgrade
redhat/grafana-pcp-debugsourceto a version that resolves this vulnerability.Fixed in 5.1.1-15.el9_6.aa
Event History
Frequently Asked Questions
Which systems and package artifacts are covered by this advisory?
The update applies to grafana-pcp and its debuginfo and debugsource packages on the listed Red Hat Enterprise Linux x86_64 and ARM 64 update channels, including SAP Solutions, Extended Update Support, AUS, and ARM 64 four-year update channels.
How should this update be prioritized?
The advisory is classified as Important, with a listed severity of high (7). It addresses CVE-2026-39821.