[CLSA-2026:1785766306] grafana: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-03 14:11:58 UTC
Description:
- CVE-2026-27879: cap the resampled series length in Series.Resample() at 1,000,000 points; the length was derived straight from the caller-supplied time range and interval and then allocated, so a crafted resample query could exhaust memory - CVE-2026-28375: bound the testdata data-source result sizes that were taken unchecked from client-controlled maxDataPoints and line counts - log lines, randomWalkTable, the simulation engine and the USA scenario are each clamped to 10000 points
Updated packages:
  • grafana-9.0.9-4.el9_2.alma.1.tuxcare.els20.x86_64.rpm
    sha:d793a1989471ed4dc7fbc1ce20874b1b302044595a0f9344318b356759c7e90d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.