Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

SUSE Grafana Medium Code Execution Denial of Service Fix 2026-2258-1

suse
Calendar Grey June 3, 2026
Dist Suse Esm H88
SUSE's grafana update addresses 12 issues, including critical denial of service and remote code execution risks. Act now!
An update that solves 12 vulnerabilities and contains one feature can now be installed.

Summary

## This update for grafana to version to 11.6.14+security01 fixes the following issues: * Security Fixes: * CVE-2026-34986: Fixed unrecoverable error in JWE decryption that could lead to a denial of service (bsc#1262950) * CVE-2026-41602: Fixed Integer Overflow or Wraparound vulnerability in Apache Thrift (bsc#1263501) * CVE-2026-26958: Ensure that MultiScalarMult properly handles initialization and produces correct results (bsc#1258595) * CVE-2026-21725: Fixed missing UID when deleting datasource by name (bsc#1258873) * CVE-2026-33375: Fixed denial of Service via out-of-memory exhaustion in MSSQL data source plugin (bsc#1260881) * CVE-2026-27876: Fixed remote arbitrary code execution via chained SQL Expressions (bsc#1261025)

References

* bsc#1258595

* bsc#1258873

* bsc#1259999

* bsc#1260263

* bsc#1260878

* bsc#1260881

* bsc#1261025

* bsc#1261026

* bsc#1261027

* bsc#1261029

* bsc#1262950

* bsc#1263501

* jsc#MSQA-1052

Cross-

* CVE-2025-29923

* CVE-2026-21724

* CVE-2026-21725

* CVE-2026-26958

* CVE-2026-27876

* CVE-2026-27877

* CVE-2026-27879

* CVE-2026-28375

* CVE-2026-33186

* CVE-2026-33375

* CVE-2026-34986

* CVE-2026-41602

CVSS scores:

* CVE-2025-29923 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

* CVE-2025-29923 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

* CVE-2026-21724 ( SUSE ): 5.3

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

* CVE-2026-21724 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Severity
moderate
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:2258-1
Release Date: 2026-06-03T14:22:06Z
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here