SUSE-SU-2026:3718-1
Vulnerability Summary
Timeline
Description
Security update for grafana This update for grafana fixes the following issues: grafana updated from version 11.6.14+security04 to version 12.4.5: Security fixes: - CVE-2026-39882: Prevent memory exhaustion DoS in OpenTelemetry OTLP HTTP exporters (bsc#1274217) - CVE-2026-33382: Limit the size of the request body before processing it at several Grafana API endpoints (bsc#1271331) - CVE-2025-12141: Fixed information leakage in Grafana Alerting (bsc#1262187) - CVE-2026-41607: Fix potential information disclosure in Apache Thrift (bsc#1263272) Breaking chahnges introduced in version 12.0.0: - BREAKING: Removed AngularJS and all deprecated UI Extensions APIs. - BREAKING: Enforced stricter version compatibility checks in plugin CLI install commands. - BREAKING: Enabled the failWrongDSUID feature flag by default, which rejects data sources with incorrect UIDs. Other changes introduced from version 11.6.14+security04 to version 12.4.5 (jsc#PED-16512): - Add Legal-Review-Notice (bsc#1271327) - Datasources: return 400 when payload UID does not match URL UID in PUT /api/datasources/uid/:uid - Analytics: Keep internal dashboard id. - Reporting: Correctly apply appSubURL to report settings requests - Alerting: Document Grafana HA Alertmanager cluster metrics prefix change. - Dependency updates to core plugins and UI libraries. - Updates to data source provisioning and dashboard schemas. - Introduced dynamic dashboards in public preview. - Added a new side toolbar that replaces the second top toolbar to provide additional vertical space. - Added the ability to create dashboards from templates using sample data. - Revamped the gauge visualization with rounded bars, configurable bar thickness, and endpoint markers. - Added support to map one variable to multiple values. - Released a completely redesigned logs visualization. - Added the ability to export dashboards directly as PNG images. - Introduced an interactive learning experience within the Grafana UI. - Added a Switch template variable type to quickly toggle between values in queries. - Added functionality to style table cells using CSS properties via the field cell option. - Added support for Entra Workload Identity to enhance authentication capabilities with federated credentials. - Redesigned the alert rule list page. - Renamed Mute Timings to Active Time Intervals in Grafana Alerting. - Added support for Service Account Impersonation in the BigQuery data source. - Introduced the Grafana Advisor in public preview. - Introduced a new dashboard schema to replace the original single grid layout. - MIGRATION: Triggered a full-table rewrite for the annotation table, which may temporarily increase disk usage.
Affected Systems
- suse•grafana&distro=SUSE Linux Enterprise Module for Package Hub 15 SP7
< 12.4.5-150200.3.91.1
References (41)
- https://www.suse.com/support/update/announcement/2026/suse-su-20263718-1/
- https://bugzilla.suse.com/1262187
- https://bugzilla.suse.com/1263272
- https://bugzilla.suse.com/1264764
- https://bugzilla.suse.com/1265281
- https://bugzilla.suse.com/1265282
- https://bugzilla.suse.com/1265283
- https://bugzilla.suse.com/1265284
- https://bugzilla.suse.com/1265285
- https://bugzilla.suse.com/1265286
- https://bugzilla.suse.com/1265287
- https://bugzilla.suse.com/1265288
- https://bugzilla.suse.com/1265289
- https://bugzilla.suse.com/1265290
- https://bugzilla.suse.com/1266600
- https://bugzilla.suse.com/1267153
- https://bugzilla.suse.com/1271327
- https://bugzilla.suse.com/1271331
- https://bugzilla.suse.com/1274217
- https://www.suse.com/security/cve/CVE-2025-12141
- https://www.suse.com/security/cve/CVE-2025-30153
- https://www.suse.com/security/cve/CVE-2026-21725
- https://www.suse.com/security/cve/CVE-2026-25680
- https://www.suse.com/security/cve/CVE-2026-25681
- https://www.suse.com/security/cve/CVE-2026-27136
- https://www.suse.com/security/cve/CVE-2026-28374
- https://www.suse.com/security/cve/CVE-2026-28376
- https://www.suse.com/security/cve/CVE-2026-28379
- https://www.suse.com/security/cve/CVE-2026-28380
- https://www.suse.com/security/cve/CVE-2026-28383
- https://www.suse.com/security/cve/CVE-2026-33376
- https://www.suse.com/security/cve/CVE-2026-33377
- https://www.suse.com/security/cve/CVE-2026-33378
- https://www.suse.com/security/cve/CVE-2026-33380
- https://www.suse.com/security/cve/CVE-2026-33381
- https://www.suse.com/security/cve/CVE-2026-33382
- https://www.suse.com/security/cve/CVE-2026-39821
- https://www.suse.com/security/cve/CVE-2026-39882
- https://www.suse.com/security/cve/CVE-2026-41607
- https://www.suse.com/security/cve/CVE-2026-42502
- https://www.suse.com/security/cve/CVE-2026-42506