[ALSA-2026:11413] Important: yggdrasil security update
Type:
security
Severity:
important
Release date:
2026-04-29
Description:
yggdrasil is a system daemon that subscribes to topics on an MQTT broker and routes any data received on the topics to an appropriate child "worker" process, exchanging data with its worker processes through a D-Bus message broker. Security Fix(es): * net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 yggdrasil-0.4.8-4.el10_1.aarch64.rpm 1ec2c2f164440f1f0a15e496284922ac4139d1f9c67a5034d17226ea6b32e687
aarch64 yggdrasil-devel-0.4.8-4.el10_1.aarch64.rpm 203229a4cb10969bcfe7a6edc8224ac955a66dca0ebc8b2dcd77d1167abdcfc0
ppc64le yggdrasil-devel-0.4.8-4.el10_1.ppc64le.rpm 501bbbab4a58992b3d14086a9d10c373457a03ff168a2e491611b31a06832fa1
ppc64le yggdrasil-0.4.8-4.el10_1.ppc64le.rpm b5dc743a47dcbb5f663d71860e5c943a53bd1e954fa28b30e247703204ef2eb7
s390x yggdrasil-devel-0.4.8-4.el10_1.s390x.rpm ad6882515d421d0608335f955bd743220f9a1349c128fc3ee5ba5f678f977e2b
s390x yggdrasil-0.4.8-4.el10_1.s390x.rpm e473c65d78b1515c4300b223a37670327e0a889cd576b87560567326a57422f3
x86_64 yggdrasil-devel-0.4.8-4.el10_1.x86_64.rpm 3e79b167f4c23556d452151fc5e48ed2b555b5bd7f487d073daa2ea2aa959922
x86_64 yggdrasil-0.4.8-4.el10_1.x86_64.rpm edf1705e75e42853a9e7f121ca0b01661167ea6edd4df80c9f49f443cbe2670b
x86_64_v2 yggdrasil-0.4.8-4.el10_1.x86_64_v2.rpm 4fe2baf7488c7d35a285371ce14293ab87ff17a96ea4547069ded363b1e191cc
x86_64_v2 yggdrasil-devel-0.4.8-4.el10_1.x86_64_v2.rpm f556c0d24ea7848f153d45e96201dbd0b292044c49bf9da0c27592462dfec827
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.