[ALSA-2026:11412] Important: yggdrasil-worker-package-manager security update
Type:
security
Severity:
important
Release date:
2026-04-29
Description:
yggdrasil-worker-package-manager is a simple package manager yggd worker. It knows how to install and remove packages, add, remove, enable and disable repositories, and does rudimentary detection of the host it is running on to guess the package manager to use. It only installs packages that match one of the provided allow-pattern regular expressions. Security Fix(es): * net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 yggdrasil-worker-package-manager-0.2.3-5.el10_1.aarch64.rpm 3e84aaf54ad912a4462b74377f547f875adf6fb2675a4c881aae0f47a3ec5fff
ppc64le yggdrasil-worker-package-manager-0.2.3-5.el10_1.ppc64le.rpm e0a6d71f128960e33d23d5ddf5a686bbabf00ea4c1bb0ac156c2437eedcab51d
s390x yggdrasil-worker-package-manager-0.2.3-5.el10_1.s390x.rpm a81c0e85b7895eda88a82d92e73fbee5164c340fcf3bce91cfe769b86ce1641e
x86_64 yggdrasil-worker-package-manager-0.2.3-5.el10_1.x86_64.rpm cd8418465587e86d6e92b412615995fbb6afcd233c29755563a8aeeee60aeaf2
x86_64_v2 yggdrasil-worker-package-manager-0.2.3-5.el10_1.x86_64_v2.rpm 9711ab87905ff3199234f134b120f45030ea6b96ec8bda8882e4fd481a132135
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.