[Apollo] Advisories Statistics light light Login

RLSA-2026:54243

Security Mirrored from RHSA-2026:54243
Issued at: 2026-09-16
Updated at: 2026-09-17

Advisory content derived from Red Hat RHSA-2026:54243, © Red Hat, Inc., used under CC BY 4.0, with modifications.

Synopsis

Important: grafana security update



Description

Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.

Security Fix(es):

* grafana: Grafana: Privilege escalation via dashboard overwrite (CVE-2026-33377)

* grafana: Grafana: Denial of Service due to excessive memory allocation via large JSON payloads (CVE-2026-42127)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 8 aarch64 Rocky Linux 8 x86_64

Fixes

2477246 2491449

CVEs

CVE-2026-33377 CVE-2026-42127

Affected packages

Rocky Linux 8 aarch64 - AppStream

grafana-0:9.2.10-32.el8_10.1.aarch64.rpm grafana-0:9.2.10-32.el8_10.1.src.rpm grafana-debuginfo-0:9.2.10-32.el8_10.1.aarch64.rpm grafana-debugsource-0:9.2.10-32.el8_10.1.aarch64.rpm grafana-selinux-0:9.2.10-32.el8_10.1.aarch64.rpm

Rocky Linux 8 x86_64 - AppStream

grafana-0:9.2.10-32.el8_10.1.src.rpm grafana-0:9.2.10-32.el8_10.1.x86_64.rpm grafana-debuginfo-0:9.2.10-32.el8_10.1.x86_64.rpm grafana-debugsource-0:9.2.10-32.el8_10.1.x86_64.rpm grafana-selinux-0:9.2.10-32.el8_10.1.x86_64.rpm