Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:34357

Опубликовано: 07 июл. 2026
Источник: rocky
Оценка: Important

Описание

Important: opentelemetry-collector security update

Collector with the supported components for a Rocky Enterprise Software Foundation build of OpenTelemetry

Security Fix(es):

  • github.com/prometheus/prometheus: Prometheus: Denial of Service via uncontrolled memory allocation in remote read endpoint (CVE-2026-42154)

  • github.com/prometheus/prometheus: Prometheus: Information disclosure of Azure OAuth client secret via config API (CVE-2026-42151)

  • net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)

  • golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)

  • golang.org/x/net/html: golang.org/x/net/html: Arbitrary code execution via Cross-Site Scripting (CVE-2026-25681)

  • crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 10

НаименованиеАрхитектураРелизRPM
opentelemetry-collectorx86_641.el10_2opentelemetry-collector-0.152.1-1.el10_2.x86_64.rpm

Показывать по

Связанные уязвимости

rocky
26 дней назад

Important: opentelemetry-collector security update

rocky
24 дня назад

Important: grafana security update

rocky
24 дня назад

Important: grafana security update

rocky
16 дней назад

Important: yggdrasil security update

oracle-oval
15 дней назад

ELSA-2026-39573: yggdrasil security update (IMPORTANT)