Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2026:58982

Опубликовано: 25 авг. 2026
Источник: rocky
Оценка: Moderate

Описание

Moderate: grafana security, bug fix, and enhancement update

Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.

Security Fix(es):

  • grafana: Grafana: Privilege escalation via dashboard overwrite (CVE-2026-33377)

  • grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default (CVE-2026-33376)

Bug Fix(es) and Enhancement(s):

  • Avoid unbounded memory growth [rhel-9.8.z] (JIRA:Rocky Linux-242865)

  • Limit the size of the request body before processing it (JIRA:Rocky Linux-242866)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 9

НаименованиеАрхитектураРелизRPM
grafanaaarch6423.el9_8.2grafana-10.2.6-23.el9_8.2.aarch64.rpm
grafana-selinuxaarch6423.el9_8.2grafana-selinux-10.2.6-23.el9_8.2.aarch64.rpm
grafanax86_6423.el9_8.2grafana-10.2.6-23.el9_8.2.x86_64.rpm
grafana-selinuxx86_6423.el9_8.2grafana-selinux-10.2.6-23.el9_8.2.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

oracle-oval
22 дня назад

ELSA-2026-58982: grafana security, bug fix, and enhancement update (MODERATE)

rocky
около 1 месяца назад

Moderate: grafana security, bug fix, and enhancement update

oracle-oval
около 1 месяца назад

ELSA-2026-54178: grafana security, bug fix, and enhancement update (MODERATE)

CVSS3: 7.4
ubuntu
4 месяца назад

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.

CVSS3: 7.4
redhat
4 месяца назад

When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask explicitly are not affected; to mitigate easily, add the desired mask (usually /128) to the addresses. Only auth proxy is affected; Okta, SAML, LDAP, etc are unaffected here.