Synopsis
Moderate: grafana-pcp security update
Type/Severity
Security Advisory: Moderate
Red Hat Lightspeed patch analysis
Identify and remediate systems affected by this advisory.
View affected systems
Topic
An update for grafana-pcp is now available for Red Hat Enterprise Linux 8.
Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.
Description
The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards.
Security Fix(es):
- golang: net/http: improper sanitization of Transfer-Encoding header (CVE-2022-1705)
- golang: io/fs: stack exhaustion in Glob (CVE-2022-30630)
- golang: compress/gzip: stack exhaustion in Reader.Read (CVE-2022-30631)
- golang: path/filepath: stack exhaustion in Glob (CVE-2022-30632)
- golang: encoding/gob: stack exhaustion in Decoder.Decode (CVE-2022-30635)
- golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working (CVE-2022-32148)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.7 Release Notes linked from the References section.
Affected Products
-
Red Hat Enterprise Linux for x86_64 8 x86_64
-
Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8 x86_64
-
Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.8 x86_64
-
Red Hat Enterprise Linux for IBM z Systems 8 s390x
-
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.8 s390x
-
Red Hat Enterprise Linux for Power, little endian 8 ppc64le
-
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.8 ppc64le
-
Red Hat Enterprise Linux Server - TUS 8.8 x86_64
-
Red Hat Enterprise Linux for ARM 64 8 aarch64
-
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.8 aarch64
-
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8 ppc64le
-
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8 x86_64
-
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64
-
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64
-
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le
-
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x
Fixes
-
BZ - 2107342
- CVE-2022-30631 golang: compress/gzip: stack exhaustion in Reader.Read
-
BZ - 2107371
- CVE-2022-30630 golang: io/fs: stack exhaustion in Glob
-
BZ - 2107374
- CVE-2022-1705 golang: net/http: improper sanitization of Transfer-Encoding header
-
BZ - 2107383
- CVE-2022-32148 golang: net/http/httputil: NewSingleHostReverseProxy - omit X-Forwarded-For not working
-
BZ - 2107386
- CVE-2022-30632 golang: path/filepath: stack exhaustion in Glob
-
BZ - 2107388
- CVE-2022-30635 golang: encoding/gob: stack exhaustion in Decoder.Decode
Note:
More recent versions of these packages may be available.
Click a package name for more details.
Red Hat Enterprise Linux for x86_64 8
| SRPM |
|
grafana-pcp-3.2.0-2.el8.src.rpm
|
SHA-256: 3d78864f49d3fc26fd16d59e4a0d3a7bbf11d5500a8c1386fa0c2b190bd5c098 |
| x86_64 |
|
grafana-pcp-3.2.0-2.el8.x86_64.rpm
|
SHA-256: 28a0df19749b6117a2cf32eccdf0b5be0813bf9cf19fde8103f9a44835161356 |
|
grafana-pcp-debuginfo-3.2.0-2.el8.x86_64.rpm
|
SHA-256: 93535f7f4b35618307729b7c962472864f411a0de88abc7501a7539fe095278b |
Red Hat Enterprise Linux for x86_64 - Extended Update Support 8.8
| SRPM |
|
grafana-pcp-3.2.0-2.el8.src.rpm
|
SHA-256: 3d78864f49d3fc26fd16d59e4a0d3a7bbf11d5500a8c1386fa0c2b190bd5c098 |
| x86_64 |
|
grafana-pcp-3.2.0-2.el8.x86_64.rpm
|
SHA-256: 28a0df19749b6117a2cf32eccdf0b5be0813bf9cf19fde8103f9a44835161356 |
|
grafana-pcp-debuginfo-3.2.0-2.el8.x86_64.rpm
|
SHA-256: 93535f7f4b35618307729b7c962472864f411a0de88abc7501a7539fe095278b |
Red Hat Enterprise Linux for x86_64 - Extended Update Support Extension 8.8
| SRPM |
|
grafana-pcp-3.2.0-2.el8.src.rpm
|
SHA-256: 3d78864f49d3fc26fd16d59e4a0d3a7bbf11d5500a8c1386fa0c2b190bd5c098 |
| x86_64 |
|
grafana-pcp-3.2.0-2.el8.x86_64.rpm
|
SHA-256: 28a0df19749b6117a2cf32eccdf0b5be0813bf9cf19fde8103f9a44835161356 |
|
grafana-pcp-debuginfo-3.2.0-2.el8.x86_64.rpm
|
SHA-256: 93535f7f4b35618307729b7c962472864f411a0de88abc7501a7539fe095278b |
Red Hat Enterprise Linux for IBM z Systems 8
| SRPM |
|
grafana-pcp-3.2.0-2.el8.src.rpm
|
SHA-256: 3d78864f49d3fc26fd16d59e4a0d3a7bbf11d5500a8c1386fa0c2b190bd5c098 |
| s390x |
|
grafana-pcp-3.2.0-2.el8.s390x.rpm
|
SHA-256: 8f78821577cb7d91321770000252ee377565eb033c4fc82cddbcfcccede80ab8 |
|
grafana-pcp-debuginfo-3.2.0-2.el8.s390x.rpm
|
SHA-256: 769939c879258b89392f5247e71c48eae5979f464a9dd271c9e188e8edf3c58e |
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 8.8
| SRPM |
|
grafana-pcp-3.2.0-2.el8.src.rpm
|
SHA-256: 3d78864f49d3fc26fd16d59e4a0d3a7bbf11d5500a8c1386fa0c2b190bd5c098 |
| s390x |
|
grafana-pcp-3.2.0-2.el8.s390x.rpm
|
SHA-256: 8f78821577cb7d91321770000252ee377565eb033c4fc82cddbcfcccede80ab8 |
|
grafana-pcp-debuginfo-3.2.0-2.el8.s390x.rpm
|
SHA-256: 769939c879258b89392f5247e71c48eae5979f464a9dd271c9e188e8edf3c58e |
Red Hat Enterprise Linux for Power, little endian 8
| SRPM |
|
grafana-pcp-3.2.0-2.el8.src.rpm
|
SHA-256: 3d78864f49d3fc26fd16d59e4a0d3a7bbf11d5500a8c1386fa0c2b190bd5c098 |
| ppc64le |
|
grafana-pcp-3.2.0-2.el8.ppc64le.rpm
|
SHA-256: 3e6172b9b3e1bee08675cc091fd512c7d90e3a6316a213b6206dd08cc4f724bd |
|
grafana-pcp-debuginfo-3.2.0-2.el8.ppc64le.rpm
|
SHA-256: 7cb610ce50eeaf56b84d2088a1475654fe6701dd72ae893b835e6eedbac1406d |
Red Hat Enterprise Linux for Power, little endian - Extended Update Support 8.8
| SRPM |
|
grafana-pcp-3.2.0-2.el8.src.rpm
|
SHA-256: 3d78864f49d3fc26fd16d59e4a0d3a7bbf11d5500a8c1386fa0c2b190bd5c098 |
| ppc64le |
|
grafana-pcp-3.2.0-2.el8.ppc64le.rpm
|
SHA-256: 3e6172b9b3e1bee08675cc091fd512c7d90e3a6316a213b6206dd08cc4f724bd |
|
grafana-pcp-debuginfo-3.2.0-2.el8.ppc64le.rpm
|
SHA-256: 7cb610ce50eeaf56b84d2088a1475654fe6701dd72ae893b835e6eedbac1406d |
Red Hat Enterprise Linux Server - TUS 8.8
| SRPM |
|
grafana-pcp-3.2.0-2.el8.src.rpm
|
SHA-256: 3d78864f49d3fc26fd16d59e4a0d3a7bbf11d5500a8c1386fa0c2b190bd5c098 |
| x86_64 |
|
grafana-pcp-3.2.0-2.el8.x86_64.rpm
|
SHA-256: 28a0df19749b6117a2cf32eccdf0b5be0813bf9cf19fde8103f9a44835161356 |
|
grafana-pcp-debuginfo-3.2.0-2.el8.x86_64.rpm
|
SHA-256: 93535f7f4b35618307729b7c962472864f411a0de88abc7501a7539fe095278b |
Red Hat Enterprise Linux for ARM 64 8
| SRPM |
|
grafana-pcp-3.2.0-2.el8.src.rpm
|
SHA-256: 3d78864f49d3fc26fd16d59e4a0d3a7bbf11d5500a8c1386fa0c2b190bd5c098 |
| aarch64 |
|
grafana-pcp-3.2.0-2.el8.aarch64.rpm
|
SHA-256: 00457fcba2aef8ba351196e8a884c372676d258a22547fcb79e9c79bbc289841 |
|
grafana-pcp-debuginfo-3.2.0-2.el8.aarch64.rpm
|
SHA-256: fbdee5a12e75c337d9cb7e15f8efcea4f4a3ea6faef0851b428ab09273055067 |
Red Hat Enterprise Linux for ARM 64 - Extended Update Support 8.8
| SRPM |
|
grafana-pcp-3.2.0-2.el8.src.rpm
|
SHA-256: 3d78864f49d3fc26fd16d59e4a0d3a7bbf11d5500a8c1386fa0c2b190bd5c098 |
| aarch64 |
|
grafana-pcp-3.2.0-2.el8.aarch64.rpm
|
SHA-256: 00457fcba2aef8ba351196e8a884c372676d258a22547fcb79e9c79bbc289841 |
|
grafana-pcp-debuginfo-3.2.0-2.el8.aarch64.rpm
|
SHA-256: fbdee5a12e75c337d9cb7e15f8efcea4f4a3ea6faef0851b428ab09273055067 |
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 8.8
| SRPM |
|
grafana-pcp-3.2.0-2.el8.src.rpm
|
SHA-256: 3d78864f49d3fc26fd16d59e4a0d3a7bbf11d5500a8c1386fa0c2b190bd5c098 |
| ppc64le |
|
grafana-pcp-3.2.0-2.el8.ppc64le.rpm
|
SHA-256: 3e6172b9b3e1bee08675cc091fd512c7d90e3a6316a213b6206dd08cc4f724bd |
|
grafana-pcp-debuginfo-3.2.0-2.el8.ppc64le.rpm
|
SHA-256: 7cb610ce50eeaf56b84d2088a1475654fe6701dd72ae893b835e6eedbac1406d |
Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 8.8
| SRPM |
|
grafana-pcp-3.2.0-2.el8.src.rpm
|
SHA-256: 3d78864f49d3fc26fd16d59e4a0d3a7bbf11d5500a8c1386fa0c2b190bd5c098 |
| x86_64 |
|
grafana-pcp-3.2.0-2.el8.x86_64.rpm
|
SHA-256: 28a0df19749b6117a2cf32eccdf0b5be0813bf9cf19fde8103f9a44835161356 |
|
grafana-pcp-debuginfo-3.2.0-2.el8.x86_64.rpm
|
SHA-256: 93535f7f4b35618307729b7c962472864f411a0de88abc7501a7539fe095278b |
Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10
| SRPM |
|
grafana-pcp-3.2.0-2.el8.src.rpm
|
SHA-256: 3d78864f49d3fc26fd16d59e4a0d3a7bbf11d5500a8c1386fa0c2b190bd5c098 |
| x86_64 |
|
grafana-pcp-3.2.0-2.el8.x86_64.rpm
|
SHA-256: 28a0df19749b6117a2cf32eccdf0b5be0813bf9cf19fde8103f9a44835161356 |
|
grafana-pcp-debuginfo-3.2.0-2.el8.x86_64.rpm
|
SHA-256: 93535f7f4b35618307729b7c962472864f411a0de88abc7501a7539fe095278b |
Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10
| SRPM |
|
grafana-pcp-3.2.0-2.el8.src.rpm
|
SHA-256: 3d78864f49d3fc26fd16d59e4a0d3a7bbf11d5500a8c1386fa0c2b190bd5c098 |
| aarch64 |
|
grafana-pcp-3.2.0-2.el8.aarch64.rpm
|
SHA-256: 00457fcba2aef8ba351196e8a884c372676d258a22547fcb79e9c79bbc289841 |
|
grafana-pcp-debuginfo-3.2.0-2.el8.aarch64.rpm
|
SHA-256: fbdee5a12e75c337d9cb7e15f8efcea4f4a3ea6faef0851b428ab09273055067 |
Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10
| SRPM |
|
grafana-pcp-3.2.0-2.el8.src.rpm
|
SHA-256: 3d78864f49d3fc26fd16d59e4a0d3a7bbf11d5500a8c1386fa0c2b190bd5c098 |
| ppc64le |
|
grafana-pcp-3.2.0-2.el8.ppc64le.rpm
|
SHA-256: 3e6172b9b3e1bee08675cc091fd512c7d90e3a6316a213b6206dd08cc4f724bd |
|
grafana-pcp-debuginfo-3.2.0-2.el8.ppc64le.rpm
|
SHA-256: 7cb610ce50eeaf56b84d2088a1475654fe6701dd72ae893b835e6eedbac1406d |
Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10
| SRPM |
|
grafana-pcp-3.2.0-2.el8.src.rpm
|
SHA-256: 3d78864f49d3fc26fd16d59e4a0d3a7bbf11d5500a8c1386fa0c2b190bd5c098 |
| s390x |
|
grafana-pcp-3.2.0-2.el8.s390x.rpm
|
SHA-256: 8f78821577cb7d91321770000252ee377565eb033c4fc82cddbcfcccede80ab8 |
|
grafana-pcp-debuginfo-3.2.0-2.el8.s390x.rpm
|
SHA-256: 769939c879258b89392f5247e71c48eae5979f464a9dd271c9e188e8edf3c58e |