Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
🔗 CVE IDs covered (14)
📋 Description
CVE-2026-28374 — grafana: Grafana: Unauthorized annotation deletion by editor users
CVE-2026-28376 — grafana: Grafana Live: Denial of Service due to unbounded memory allocation via push endpoint
CVE-2026-28379 — grafana: Grafana Live: Denial of Service due to a race condition
CVE-2026-28380 — grafana: Grafana: Unauthorized snapshot deletion via Broken Access Control in Snapshot API
CVE-2026-28383 — grafana: Grafana: Denial of Service via unbounded memory allocation in plugin resources endpoint
CVE-2026-33376 — grafana: Grafana Auth Proxy: Unauthorized access due to incorrect IPv6 allow-list default
CVE-2026-33377 — grafana: Grafana: Privilege escalation via dashboard overwrite
CVE-2026-33378 — grafana: Grafana: Denial of Service due to Out of Memory via $__timeGroup macro
CVE-2026-33380 — grafana: Grafana: Information disclosure via SQL Expressions vulnerability
CVE-2026-33381 — grafana: Grafana: Temporary access control bypass for service account token minting
CVE-2026-61709 — github.com/openfga/openfga: OpenFGA: Unauthorized access due to ListUsers API returning deliberately excluded users.
CVE-2026-81871 — go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploggrpc: OpenTelemetry-Go: TLS certificate bypass allows log telemetry interception and alteration
CVE-2026-81872 — go.opentelemetry.io/otel/sdk/log: OpenTelemetry-Go: Denial of Service via attacker-driven log emission
CVE-2026-92599 — joi: joi: Denial of Service via isoDate validation regular expression
🎯 Affected products4
- Red Hat Hardened Images
- grafana12.4-0:12.4.10-0.6.hum1@aarch64 as a component of Red Hat Hardened Images
- grafana12.4-0:12.4.10-0.6.hum1@src as a component of Red Hat Hardened Images
- grafana12.4-0:12.4.10-0.6.hum1@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, explicitly specify the intended IPv6 address mask—typically /128 for a single host—within the Grafana Auth Proxy allow-list configuration. This overrides the incorrect default /32 mask, ensuring that network access restrictions are applied strictly as intended. For RHEL: Update the whitelist directive under the [auth.proxy] section in /etc/grafana/grafana.ini. For example, if ::1 is the desired address, configure it explicitly as ::1/128. A restart of the Grafana service (systemctl restart grafana-server) is required for the changes to take effect. Workaround: Audit dashboard-level permissions to ensure that write access is granted only to users who should be able to modify each specific dashboard. Revoke per-dashboard write permissions from Editor users who do not strictly require them. Workaround: No product-side mitigation is required while Zanzana remains disabled, which is the default. If Zanzana has been turned on, do not use ListUsers results as an access-control decision; use Check for each user and object until Grafana vendors OpenFGA 1.18.1 or later. Workaround: To mitigate this vulnerability, ensure that any input strings processed by the `Joi.string().isoDate()` validation rule are capped in length before being passed to the 'joi' package. This can prevent the regular expression engine from consuming excessive resources and causing a denial of service.
🔗 References (18)
- selfhttps://access.redhat.com/errata/RHSA-2026:68821
- externalhttps://access.redhat.com/security/cve/CVE-2026-61709
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-33380
- externalhttps://access.redhat.com/security/cve/CVE-2026-33378
- externalhttps://access.redhat.com/security/cve/CVE-2026-28374
- externalhttps://access.redhat.com/security/cve/CVE-2026-33377
- externalhttps://access.redhat.com/security/cve/CVE-2026-33376
- externalhttps://access.redhat.com/security/cve/CVE-2026-28380
- externalhttps://access.redhat.com/security/cve/CVE-2026-33381
- externalhttps://access.redhat.com/security/cve/CVE-2026-28376
- externalhttps://access.redhat.com/security/cve/CVE-2026-28379
- externalhttps://access.redhat.com/security/cve/CVE-2026-28383
- externalhttps://access.redhat.com/security/cve/CVE-2026-81872
- externalhttps://access.redhat.com/security/cve/CVE-2026-81871
- externalhttps://access.redhat.com/security/cve/CVE-2026-92599
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_68821.json