[ALSA-2026:19126] Important: yggdrasil security update
Type:
security
Severity:
important
Release date:
2026-05-26
Description:
yggdrasil is a system daemon that subscribes to topics on an MQTT broker and routes any data received on the topics to an appropriate child "worker" process, exchanging data with its worker processes through a D-Bus message broker. Security Fix(es): * net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) * crypto/tls: golang: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 yggdrasil-devel-0.4.9-4.el10_2.aarch64.rpm 098e7c9e5302d9d82f030e11edb3ad4a2c873127589817ecad6141929b26756d
aarch64 yggdrasil-0.4.9-4.el10_2.aarch64.rpm ec2a13fa71a6927a72a0f8b7dda2ee6fa2416c8af76d3c954115d762c795081e
ppc64le yggdrasil-devel-0.4.9-4.el10_2.ppc64le.rpm 8c93a2dcd6a7284bce9994588610c0125935d6f5a56a6a542422e92f4e5b387c
ppc64le yggdrasil-0.4.9-4.el10_2.ppc64le.rpm bd247ee31d66e84c57578bfac63888cbd257f84a134af1468b5a149cc8d33640
s390x yggdrasil-0.4.9-4.el10_2.s390x.rpm 13b403a820c97a4cbacbc7c82f2b77461e2ee1a242387834bd431e37ef27e1b5
s390x yggdrasil-devel-0.4.9-4.el10_2.s390x.rpm b0e13767f01e49732a5f232b953aac704803cc4c0bf4e87bb9fcc11f90fcc977
x86_64 yggdrasil-0.4.9-4.el10_2.x86_64.rpm bc54535ff17a4f1ce9e0152de2c7eb6d75ae436c6fc922f7b314e1efc965c823
x86_64 yggdrasil-devel-0.4.9-4.el10_2.x86_64.rpm f508b5bc547bf80da60e2193a81233fa47c95a020b4565b923413dfbfed594ad
x86_64_v2 yggdrasil-0.4.9-4.el10_2.x86_64_v2.rpm 6d92390290fa04bac5b04eaa245c071f8800a49cc79f5332179c1db341a4a6e9
x86_64_v2 yggdrasil-devel-0.4.9-4.el10_2.x86_64_v2.rpm d0d891ea3455b06c0bf436e57499b66d113c5a431578887ab7a8d8bc15ec5eee
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.