[ALSA-2026:39573] Important: yggdrasil security update
Type:
security
Severity:
important
Release date:
2026-07-21
Description:
yggdrasil is a system daemon that subscribes to topics on an MQTT broker and routes any data received on the topics to an appropriate child "worker" process, exchanging data with its worker processes through a D-Bus message broker. Security Fix(es): * net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) * golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) * crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 yggdrasil-devel-0.4.9.2-1.el10_2.aarch64.rpm a57a0dadb8b460c30142f24c07a9925475ad601c076473a4f21f04afc791c42c
aarch64 yggdrasil-0.4.9.2-1.el10_2.aarch64.rpm aa83a55f0c9023b5cde3ec5bbc13a394a149879fb0fd109b0668bd0bdefc1181
ppc64le yggdrasil-devel-0.4.9.2-1.el10_2.ppc64le.rpm 37d60bb8349036b76ca32a14bd9b4fcc2d6904cade9460ca62761f0cbe20ed2c
ppc64le yggdrasil-0.4.9.2-1.el10_2.ppc64le.rpm 872362f8b5b1d3ee3a47cd2da2b916b8f19d939b31097a11af30b93e6567426e
s390x yggdrasil-0.4.9.2-1.el10_2.s390x.rpm 65291382513926d418018ec20acb841bc3fbc899ebf874da9ccd4de12630656b
s390x yggdrasil-devel-0.4.9.2-1.el10_2.s390x.rpm feecc91dfa057f2f84c7044b7198e2ad36942f98a9e597acf8857613878dc960
x86_64 yggdrasil-0.4.9.2-1.el10_2.x86_64.rpm 6fd2d13f76b5df9110797da6f6f45e6c556293d722de84cef9c4067509bfc6db
x86_64 yggdrasil-devel-0.4.9.2-1.el10_2.x86_64.rpm c46af0e1755605a310325ea122bc87df9c0f5c67ac0526d736e5d2dc350707cb
x86_64_v2 yggdrasil-devel-0.4.9.2-1.el10_2.x86_64_v2.rpm 82f584c5af6c23e813994719b346c9844717297518c0101c8b79982001c65a4c
x86_64_v2 yggdrasil-0.4.9.2-1.el10_2.x86_64_v2.rpm cf212c0717f037fd48ffaa6af569695e835c4ecfca94ed8a44316751400a7da6
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.