ELSA-2026-6382

ELSA-2026-6382 - grafana security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-04-01

Description


[10.2.6-19]
- Resolves RHEL-158728: CVE-2026-25679

[10.2.6-17]
- Resolves RHEL-144959: CVE-2026-21721
- Resolves RHEL-146863: CVE-2025-61726
- Resolves RHEL-147081: CVE-2025-61729
- Resolves RHEL-147370: CVE-2025-61728
- Resolves RHEL-149621: CVE-2025-68121

[10.2.6-17]
- Resolves RHEL-125692: CVE-2025-58183
- Resolves RHEL-120426: Grafana-selinux prevents plugins from searching cgroups

[10.2.6-15]
- Resolves RHEL-97518: Rework grafana-selinux spec file sections
- Resolves RHEL-87861: Add additional SELinux rules for grafana-selinux package to allow LDAP connections

[10.2.6-13]
- Resolves RHEL-89953: CVE-2025-4123

[10.2.6-12]
- Resolves RHEL-85419: Move grafana home directory to /var/lib/grafana

[10.2.6-11]
- Resolves RHEL-84636: CVE-2025-30204

[10.2.6-10]
- Resolves RHEL-75919: grafana selinux issue with autofs_t

[10.2.6-9]
- Resolves RHEL-69939: allow mssql datasource in selinux policy

[10.2.6-8]
- Resolves RHEL-62312: CVE-2024-47875


Related CVEs


CVE-2026-25679

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) grafana-10.2.6-19.el9_7.src.rpm3b648b122eb7831f9eb597b1b1080dd7157fff4460ff601942113866e0b93226-ol9_aarch64_appstream
grafana-10.2.6-19.el9_7.aarch64.rpm35eb5ac54d39b36376a19da0181aa9463a45690fdf75e71e5ef79ed74efe9fcd-ol9_aarch64_appstream
grafana-selinux-10.2.6-19.el9_7.aarch64.rpm1ab535bb63aad6401c0f5249a511767fd4f554814fba2ea05fe05a7ca45fe43f-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) grafana-10.2.6-19.el9_7.src.rpm3b648b122eb7831f9eb597b1b1080dd7157fff4460ff601942113866e0b93226-ol9_x86_64_appstream
grafana-10.2.6-19.el9_7.x86_64.rpm14a5879d6a3dc9c51528496c5d329ebb6398fd0ab28a2f4bd7c02565d46f32dc-ol9_x86_64_appstream
grafana-selinux-10.2.6-19.el9_7.x86_64.rpmf52b781ee99e80f284c70774e34bbf146b6b6ffa787b10dde940dc8da9722f0a-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete