Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:8667 - Security Advisory
Issued:
2025-06-09
Updated:
2025-06-09

RHSA-2025:8667 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: grafana security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for grafana is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.

Security Fix(es):

  • net/http: Request smuggling due to acceptance of invalid chunked data in net/http (CVE-2025-22871)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 2358493 - CVE-2025-22871 net/http: Request smuggling due to acceptance of invalid chunked data in net/http

CVEs

  • CVE-2025-22871

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
grafana-9.2.10-25.el8_10.src.rpm SHA-256: 5ffc33f302b350184344ee4b107cc6fbaf6d847edfc8229e8514d35518d167f0
x86_64
grafana-9.2.10-25.el8_10.x86_64.rpm SHA-256: 6e3dbaf65f9af346f9f2de2a6a3c3ed2497f78ac58ac24fac0ad5f1d24ca0752
grafana-debuginfo-9.2.10-25.el8_10.x86_64.rpm SHA-256: b6d3ab9391606f471551dc10bcc5293da16c4fe3c3083337f81ef480933c7fe7
grafana-debugsource-9.2.10-25.el8_10.x86_64.rpm SHA-256: c32715c3e87600317e4db332987748dbaa8fbb080f5ce9e5df7cc0ce62950edd
grafana-selinux-9.2.10-25.el8_10.x86_64.rpm SHA-256: a7cf4af5b4f1faf2e7c97714b517538d07a245ffd9d4dc2428ae52cba51e7e6f

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
grafana-9.2.10-25.el8_10.src.rpm SHA-256: 5ffc33f302b350184344ee4b107cc6fbaf6d847edfc8229e8514d35518d167f0
s390x
grafana-9.2.10-25.el8_10.s390x.rpm SHA-256: ce55ec943a1d038c69ccb785f7ce43401ec4c6602cb53d607e0a0c57c29c4444
grafana-debuginfo-9.2.10-25.el8_10.s390x.rpm SHA-256: 86629aa346047af6411a00f39ce397828ce2e5ca307ebc8155ffd8d8cbefe8a5
grafana-debugsource-9.2.10-25.el8_10.s390x.rpm SHA-256: 8c98a33f71fbd176481d03752524866a58ff48382dc80632c2a282d87076349a
grafana-selinux-9.2.10-25.el8_10.s390x.rpm SHA-256: cf4de6385c69430fc813a03f96d301869773ad8cd520f0c82281364ea4faa950

Red Hat Enterprise Linux for Power, little endian 8

SRPM
grafana-9.2.10-25.el8_10.src.rpm SHA-256: 5ffc33f302b350184344ee4b107cc6fbaf6d847edfc8229e8514d35518d167f0
ppc64le
grafana-9.2.10-25.el8_10.ppc64le.rpm SHA-256: 3a46271c2835f3465f8f73d398f8dfb626962f8cac79641f65b3f90925967c72
grafana-debuginfo-9.2.10-25.el8_10.ppc64le.rpm SHA-256: 4f409461fdf8871281bf0b64a3cc91c37f62114ad45ca385f8082fbba1966dd6
grafana-debugsource-9.2.10-25.el8_10.ppc64le.rpm SHA-256: 38bf91be448a2353b1f1d57f5b9aa7bd9015b0b2527e83ab0d5f6d46ccfaa62d
grafana-selinux-9.2.10-25.el8_10.ppc64le.rpm SHA-256: fbccfe0fe568ed51c1cc83ac91fddb15673622ec80b3c74d83860829f091b43d

Red Hat Enterprise Linux for ARM 64 8

SRPM
grafana-9.2.10-25.el8_10.src.rpm SHA-256: 5ffc33f302b350184344ee4b107cc6fbaf6d847edfc8229e8514d35518d167f0
aarch64
grafana-9.2.10-25.el8_10.aarch64.rpm SHA-256: 90f3fb5709f3ab1bc60a6aec621cd35bb35d291e68044816d5040bb08e77cd74
grafana-debuginfo-9.2.10-25.el8_10.aarch64.rpm SHA-256: d9005398d1600d1d77f2a9519511a3bfe093dcbf89a1900c626fe8c915f9692b
grafana-debugsource-9.2.10-25.el8_10.aarch64.rpm SHA-256: 5b4d7630b60f1d4da0ae237567b40b91da5dbfc07ca12a9668e229a1de4c4049
grafana-selinux-9.2.10-25.el8_10.aarch64.rpm SHA-256: 6de29f283cf3918eca4d1b8bb29b4d1c470668db036675ffed1184fa52a1d6d2

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility