[ALSA-2026:46394] Important: go-fdo-client security update
Type:
security
Severity:
important
Release date:
2026-07-28
Description:
go-fdo-client is the device-side implementation of FIDO Device Onboard specification in Go. It provides an FDO client that interacts with FDO manufacturer and owner servers to perform device on-boarding. Security Fix(es): * crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 go-fdo-client-1.0.0-4.el10_2.5.aarch64.rpm ebeb8f6ec5269d0f579bba5ff27d11f5eb2edc3e32d1816e3ce34d6739921542
x86_64 go-fdo-client-1.0.0-4.el10_2.5.x86_64.rpm 1736d1f74d3b36dec4fd0e8fd1ab31d05bca3c5e5bce11dc17d5b29574ddb8a0
x86_64_v2 go-fdo-client-1.0.0-4.el10_2.5.x86_64_v2.rpm 09b2315b63b01d4c2d044ffde9d6b85a35c7dc183a7e7e9a696b86a75b5694c6
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.