Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2026:6344 - Security Advisory
Issued:
2026-04-01
Updated:
2026-04-01

RHSA-2026:6344 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Important: grafana security update

Type/Severity

Security Advisory: Important

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for grafana is now available for Red Hat Enterprise Linux 10.

Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Grafana is an open source, feature rich metrics dashboard and graph editor for Graphite, InfluxDB & OpenTSDB.

Security Fix(es):

  • net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 10 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 10 s390x
  • Red Hat Enterprise Linux for Power, little endian 10 ppc64le
  • Red Hat Enterprise Linux for ARM 64 10 aarch64

Fixes

  • BZ - 2445356 - CVE-2026-25679 net/url: Incorrect parsing of IPv6 host literals in net/url

CVEs

  • CVE-2026-25679

References

  • https://access.redhat.com/security/updates/classification/#important
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 10

SRPM
grafana-10.2.6-23.el10_1.src.rpm SHA-256: db1318e6a9639dc32d827fffc57bbf99facfe37c077083b9a484bc2376134bdb
x86_64
grafana-10.2.6-23.el10_1.x86_64.rpm SHA-256: f0621c4669c48deb0de7cd4547a96a0ac68c0b7862b0117f93f72b23934df599
grafana-debuginfo-10.2.6-23.el10_1.x86_64.rpm SHA-256: d41bd1c0e2fba1699fa6524923e38e78946121691a11af0e08ed6fac8d25ca07
grafana-debugsource-10.2.6-23.el10_1.x86_64.rpm SHA-256: 2f7f23035ed25e28049f6a1b894d00a3f37e4ba71edf9e3424c378b72ff2b8ad
grafana-selinux-10.2.6-23.el10_1.x86_64.rpm SHA-256: d17e35dc9d1a06eaeac2462673fece502d35752d210571a22aa2a24a95dac178

Red Hat Enterprise Linux for IBM z Systems 10

SRPM
grafana-10.2.6-23.el10_1.src.rpm SHA-256: db1318e6a9639dc32d827fffc57bbf99facfe37c077083b9a484bc2376134bdb
s390x
grafana-10.2.6-23.el10_1.s390x.rpm SHA-256: 5db4536f49cbceb8f20924aeca8302cbebbaae45c3932a2e9375255a0d142c17
grafana-debuginfo-10.2.6-23.el10_1.s390x.rpm SHA-256: 4ee49ef1821284954bc944cad354f99f47da85ad8abaf7cb0746ae424b1d8eff
grafana-debugsource-10.2.6-23.el10_1.s390x.rpm SHA-256: 87afc284cef11e35bd5e3925b4c279378693aa0c3665046008ff0e2790b4ddcc
grafana-selinux-10.2.6-23.el10_1.s390x.rpm SHA-256: 86d34ca5d7a3fc765599fd42a2f13f5fecac9b1742346a817a842f79e4ca0e40

Red Hat Enterprise Linux for Power, little endian 10

SRPM
grafana-10.2.6-23.el10_1.src.rpm SHA-256: db1318e6a9639dc32d827fffc57bbf99facfe37c077083b9a484bc2376134bdb
ppc64le
grafana-10.2.6-23.el10_1.ppc64le.rpm SHA-256: bcda8d0532a68ff2ec2b9f7460017eea878be75103b7a64cfbddc0bc7090d3c4
grafana-debuginfo-10.2.6-23.el10_1.ppc64le.rpm SHA-256: 4312e185f9d4dc0f142e58b886460706eca87adb24e1017a7b99aadd4b71ca3e
grafana-debugsource-10.2.6-23.el10_1.ppc64le.rpm SHA-256: 4e6ee4204dd65635ba0fac5f5bc0abccbe336ca37eeab1206d1133f862e4ffa9
grafana-selinux-10.2.6-23.el10_1.ppc64le.rpm SHA-256: f2cb037d364c5f1b6435d8077212cd5d254685609bd37c1da625ee5217f95767

Red Hat Enterprise Linux for ARM 64 10

SRPM
grafana-10.2.6-23.el10_1.src.rpm SHA-256: db1318e6a9639dc32d827fffc57bbf99facfe37c077083b9a484bc2376134bdb
aarch64
grafana-10.2.6-23.el10_1.aarch64.rpm SHA-256: 9d300d94d667ea19cf5f6c8e9198e3eff3d376d8ddbc6e7ca38ac97f8a1505f7
grafana-debuginfo-10.2.6-23.el10_1.aarch64.rpm SHA-256: 9b1a5ed567ae0ec453e4e6815a73a42fa86760fe6a3fcd82e7311333a4cb2785
grafana-debugsource-10.2.6-23.el10_1.aarch64.rpm SHA-256: 9bfed4c7bc47d528c670abfaafce86200bf752452c9f821557fa64723e2d4780
grafana-selinux-10.2.6-23.el10_1.aarch64.rpm SHA-256: 5c88dc8e4e3947deee9e70bde389d72b3358b021d2dbea49c78ab2afc208e894

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility