import grafana-9.2.10-17.el9_4

i9c changed/i9c/grafana-9.2.10-17.el9_4
MSVSphere Packaging Team 2 months ago
parent d6482aebaa
commit 58a1bf4a62
Signed by: sys_gitsync
GPG Key ID: B2B0B9F29E528FE8

@ -2,7 +2,7 @@ use pbkdf2 from OpenSSL if FIPS mode is enabled
This patch modifies the x/crypto/pbkdf2 function to use OpenSSL
if FIPS mode is enabled.
DEFINEFUNC is from /usr/lib/golang/src/vendor/github.com/golang-fips/openssl-fips/openssl/goopenssl.h
DEFINEFUNC is from /usr/lib/golang/src/vendor/github.com/golang-fips/openssl/openssl/goopenssl.h
diff --git a/vendor/golang.org/x/crypto/internal/boring/boring.go b/vendor/golang.org/x/crypto/internal/boring/boring.go
new file mode 100644
@ -112,7 +112,7 @@ index 0000000000..6dfdf10424
--- /dev/null
+++ b/vendor/golang.org/x/crypto/internal/boring/openssl_pbkdf2.h
@@ -0,0 +1,5 @@
+#include "/usr/lib/golang/src/vendor/github.com/golang-fips/openssl-fips/openssl/goopenssl.h"
+#include "/usr/lib/golang/src/vendor/github.com/golang-fips/openssl/openssl/goopenssl.h"
+
+DEFINEFUNC(int, PKCS5_PBKDF2_HMAC,
+ (const char *pass, int passlen, const unsigned char *salt, int saltlen, int iter, EVP_MD *digest, int keylen, unsigned char *out),

@ -25,7 +25,7 @@ end}
Name: grafana
Version: 9.2.10
Release: 16%{?dist}
Release: 17%{?dist}
Summary: Metrics dashboard and graph editor
License: AGPL-3.0-only
URL: https://grafana.org
@ -1010,6 +1010,9 @@ fi
%{_datadir}/selinux/*/grafana.pp
%changelog
* Tue Sep 17 2024 Sam Feifer <sfeifer@redhat.com> 9.2.10-17
- Resolves RHEL-57925: CVE-2024-34156
* Tue Apr 16 2024 Sam Feifer <sfeifer@redhat.com> 9.2.10-16
- Check OrdID is correct before deleting snapshot
- fix CVE-2024-1313

Loading…
Cancel
Save