[ALSA-2025:7592] Important: yggdrasil security update
Type:
security
Severity:
important
Release date:
2025-07-28
Description:
yggdrasil is a system daemon that subscribes to topics on an MQTT broker and routes any data received on the topics to an appropriate child "worker" process, exchanging data with its worker processes through a D-Bus message broker. Security Fix(es): * yggdrasil: Local privilege escalation in yggdrasil (CVE-2025-3931) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 yggdrasil-devel-0.4.5-3.el10_0.aarch64.rpm 63d74cc162ad1c274e083ddf6d77dfbb4c0f2481c38528629df7bb1303bbb6e3
aarch64 yggdrasil-0.4.5-3.el10_0.aarch64.rpm f71cc315e852df300e731db190a81111becc5ca43d9583224d629904fa6b53ce
ppc64le yggdrasil-devel-0.4.5-3.el10_0.ppc64le.rpm 791e868651ee42bf41e1e9695a676b48fc658f2281f75fd2a96f296b667d72b9
ppc64le yggdrasil-0.4.5-3.el10_0.ppc64le.rpm 9ec2f3899ff2899911d8ebd743c77f3f60f86e7b10d74b72fc109578e32d4525
s390x yggdrasil-0.4.5-3.el10_0.s390x.rpm 0b952c18010340cdc7a539e0a99c87dc1bf4b7b637c9f1f1f4a7cc852e91cea6
s390x yggdrasil-devel-0.4.5-3.el10_0.s390x.rpm 727f998c48b802a049b9e9f93a8d8458ba803221af53543ef4ee779ff36f9433
x86_64 yggdrasil-0.4.5-3.el10_0.x86_64.rpm 363a15d5565b941d7f3cccc322069e75e7f598bdfabbaac9a13f0651dc0ab4e7
x86_64 yggdrasil-devel-0.4.5-3.el10_0.x86_64.rpm 4f0f7a4c8c3859b3d5c67536ea229f5e32b2a2c7239a7b24c813f04026715b99
x86_64_v2 yggdrasil-0.4.5-3.el10_0.x86_64_v2.rpm 4f2193da43e2f356d9ff8c13e9f9df50cba26f2ed1a80c12a4a8882923276a14
x86_64_v2 yggdrasil-devel-0.4.5-3.el10_0.x86_64_v2.rpm 5da2dea6dbefc5f3f44e38cfba724a9806c165074226cc34ab02addf6ee64021
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.