[CLSA-2026:1779152708] grafana: Fix of CVE-2026-32283
Type:
security
Severity:
Important
Release date:
2026-05-19 01:05:12 UTC
Description:
- CVE-2026-32283: rebuild against golang >= 1.25.7-1.el9_6.tuxcare.els5 to fix crypto/tls DoS where multiple post-handshake KeyUpdate messages in a single TLS 1.3 record deadlock the connection (setReadTrafficSecret reacquired the conn mutex via sendAlert)
Updated packages:
  • grafana-10.2.6-15.el9_6.tuxcare.els8.x86_64.rpm
    sha:ac81ace1dcfd3def74bb5e6d60826654d721566dc7b8334afabe4fe16020ef73
  • grafana-selinux-10.2.6-15.el9_6.tuxcare.els8.x86_64.rpm
    sha:8baa6b38f456b16b2fe2fec9590fa81050f5716bbbaf6791529709d72d013d23
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.