[ALSA-2024:1644] grafana-pcp security and bug fix update

Severity Important
Affected Packages 2
CVEs 1

grafana-pcp security and bug fix update

The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards.

Security Fix(es):

  • golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (CVE-2024-1394)

Bug Fix(es):

  • TRIAGE CVE-2024-1394 grafana-pcp: golang-fips/openssl: Memory leaks in code encrypting and decrypting RSA payloads (JIRA:AlmaLinux-30544)
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/almalinux/grafana-pcp?arch=x86_64&distro=almalinux-8.9 almalinux grafana-pcp < 5.1.1-2.el8_9.alma.1 almalinux-8.9 x86_64
Affected pkg:rpm/almalinux/grafana-pcp?arch=aarch64&distro=almalinux-8.9 almalinux grafana-pcp < 5.1.1-2.el8_9.alma.1 almalinux-8.9 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...