[ALSA-2026:19128] Important: yggdrasil-worker-package-manager security update
Type:
security
Severity:
important
Release date:
2026-05-26
Description:
yggdrasil-worker-package-manager is a simple package manager yggd worker. It knows how to install and remove packages, add, remove, enable and disable repositories, and does rudimentary detection of the host it is running on to guess the package manager to use. It only installs packages that match one of the provided allow-pattern regular expressions. Security Fix(es): * net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 yggdrasil-worker-package-manager-0.2.3-6.el10_2.aarch64.rpm 3f1e8c48eabdc01d6979e11eb3916bfa8936400a681ccb2fcdf10b35ab59a880
ppc64le yggdrasil-worker-package-manager-0.2.3-6.el10_2.ppc64le.rpm ec8478e23af881e060b9a5363fc12ddf7db61923bbdc258b8ed4937fa86bccdb
s390x yggdrasil-worker-package-manager-0.2.3-6.el10_2.s390x.rpm a73de8fe33dabaa4e77f605339670aff9046f6d5574aab16cf5c4f106b60e5b9
x86_64 yggdrasil-worker-package-manager-0.2.3-6.el10_2.x86_64.rpm 6d2acb944b80190afddecd088d3f82c3dfe519078946776a8db3cba8933b1b14
x86_64_v2 yggdrasil-worker-package-manager-0.2.3-6.el10_2.x86_64_v2.rpm ac83c67038b6479c4009afc0e356a8d27a9124ad9b560eff09c4ed37d8a54b6b
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.