Important: grafana-pcp security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:7009", "synopsis": "Important: grafana-pcp security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for grafana-pcp.\nThis update affects Rocky Linux 8.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "The Grafana plugin for Performance Co-Pilot includes datasources for scalable time series from pmseries and Redis, live PCP metrics and bpftrace scripts from pmdabpftrace, as well as several dashboards.\n\nSecurity Fix(es):\n\n* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 8"], "fixes": [{"ticket": "2445356", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", "description": ""}], "cves": [{"name": "CVE-2026-25679", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-25679", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-1286"}], "references": [], "publishedAt": "2026-04-10T12:01:16.786705Z", "rpms": {"Rocky Linux 8": {"nvras": ["grafana-pcp-0:5.1.1-13.el8_10.aarch64.rpm", "grafana-pcp-0:5.1.1-13.el8_10.src.rpm", "grafana-pcp-0:5.1.1-13.el8_10.x86_64.rpm", "grafana-pcp-debuginfo-0:5.1.1-13.el8_10.aarch64.rpm", "grafana-pcp-debuginfo-0:5.1.1-13.el8_10.x86_64.rpm", "grafana-pcp-debugsource-0:5.1.1-13.el8_10.aarch64.rpm", "grafana-pcp-debugsource-0:5.1.1-13.el8_10.x86_64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important grafana-pcp security update for Rocky Linux addressing potential threats and severe impacts. Act now!. Rocky Linux grafana-pcp securityimportant update. . Severity: Important. LinuxSecurity.com Team
Patch the code to use https instead of http (CVE-2024-45321). -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2024-aaa468ae4f 2024-10-09 01:29:48.658001 -------------------------------------------------------------------------------- Name : perl-App-cpanminus Product : Fedora 40 Version : 1.7047 Release : 4.fc40 URL : https://metacpan.org/dist/App-cpanminus Summary : Get, unpack, build and install CPAN modules Description : Why? It's dependency free, requires zero configuration, and stands alone but it's maintainable and extensible with plug-ins and friendly to shell scripting. When running, it requires only 10 MB of RAM. -------------------------------------------------------------------------------- Update Information: Patch the code to use https instead of http (CVE-2024-45321) -------------------------------------------------------------------------------- ChangeLog: * Thu Sep 26 2024 Jitka Plesnikova - 1.7047-4 - Patch the code to use https instead of http (CVE-2024-45321) -------------------------------------------------------------------------------- References: [ 1 ] Bug #2308439 - CVE-2024-45321 perl-App-cpanminus: From NVD collector [fedora-40] https://bugzilla.redhat.com/show_bug.cgi?id=2308439 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2024-aaa468ae4f' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list
Several security issues were fixed in WebKitGTK+.. =========================================================================Ubuntu Security Notice USN-2937-1 March 21, 2016 webkitgtk vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 15.10 - Ubuntu 14.04 LTS Summary: Several security issues were fixed in WebKitGTK+. Software Description: - webkitgtk: Web content engine library for GTK+ Details: A large number of security issues were discovered in the WebKitGTK+ Web and JavaScript engines. If a user were tricked into viewing a malicious website, a remote attacker could exploit a variety of issues related to web browser security, including cross-site scripting attacks, denial of service attacks, and arbitrary code execution. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: libjavascriptcoregtk-1.0-0 2.4.10-0ubuntu0.15.10.1 libjavascriptcoregtk-3.0-0 2.4.10-0ubuntu0.15.10.1 libwebkitgtk-1.0-0 2.4.10-0ubuntu0.15.10.1 libwebkitgtk-3.0-0 2.4.10-0ubuntu0.15.10.1 Ubuntu 14.04 LTS: libjavascriptcoregtk-1.0-0 2.4.10-0ubuntu0.14.04.1 libjavascriptcoregtk-3.0-0 2.4.10-0ubuntu0.14.04.1 libwebkitgtk-1.0-0 2.4.10-0ubuntu0.14.04.1 libwebkitgtk-3.0-0 2.4.10-0ubuntu0.14.04.1 This update uses a new upstream release, which includes additional bug fixes. After a standard system update you need to restart any applications that use WebKitGTK+, such as Epiphany and Evolution, to make all the necessary changes. References: https://ubuntu.com/security/notices/USN-2937-1 CVE-2014-1748, CVE-2015-1071, CVE-2015-1076, CVE-2015-1081, CVE-2015-1083, CVE-2015-1120, CVE-2015-1122, CVE-2015-1127, CVE-2015-1153, CVE-2015-1155, CVE-2015-3658, CVE-2015-3659, CVE-2015-3727, CVE-2015-3731,CVE-2015-3741, CVE-2015-3743, CVE-2015-3745, CVE-2015-3747, CVE-2015-3748, CVE-2015-3749, CVE-2015-3752, CVE-2015-5788, CVE-2015-5794, CVE-2015-5801, CVE-2015-5809, CVE-2015-5822, CVE-2015-5928 Package Information: https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.15.10.1 https://launchpad.net/ubuntu/+source/webkitgtk/2.4.10-0ubuntu0.14.04.1 . This patch resolves essential vulnerabilities in WebKitGTK+ impacting Ubuntu 16.04 and 14.10 LTS, improving online safety.. WebKitGTK, Remote Code Execution, Cross-Site Scripting, Denial of Service. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.