[ALSA-2026:57126] Important: yggdrasil security update
Type:
security
Severity:
important
Release date:
2026-08-20
Description:
yggdrasil is a system daemon that subscribes to topics on an MQTT broker and routes any data received on the topics to an appropriate child "worker" process, exchanging data with its worker processes through a D-Bus message broker. Security Fix(es): * crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 yggdrasil-0.4.9.2-1.el10_2.2.aarch64.rpm 15015f4482bdc52efa73db6c5ac8ba3dc0174805246d90b333ffa5068b4390cd
aarch64 yggdrasil-devel-0.4.9.2-1.el10_2.2.aarch64.rpm 8729eb65f7deb77253c9cd56d6834503ad234da230ed63b7a71d43f73c4a3d68
ppc64le yggdrasil-0.4.9.2-1.el10_2.2.ppc64le.rpm 4e1dda5e3ab1fa3cc0b1f9e73f7e23dcc2adc95f892ea8cde4796103dbaa1684
ppc64le yggdrasil-devel-0.4.9.2-1.el10_2.2.ppc64le.rpm 6c3aaa68ce7237fbc024cc48afb4b7f4e1ae079c71b0ac5320d1760aef8dab85
s390x yggdrasil-0.4.9.2-1.el10_2.2.s390x.rpm 0a24f45f05bb7040629c6216c94f28a534a2650e528a2419deb3b7e2e34944cf
s390x yggdrasil-devel-0.4.9.2-1.el10_2.2.s390x.rpm 6ebf69451b24825aae87225705be3f4174b8ad3939998ccebf66b8574b1097d9
x86_64 yggdrasil-devel-0.4.9.2-1.el10_2.2.x86_64.rpm 285ffc347ce3f97dfe25182e34338a95bb5be28875e9eab7dd3935e61e385cb7
x86_64 yggdrasil-0.4.9.2-1.el10_2.2.x86_64.rpm f7b3d69bb1457d588b7192a2461cc6e1f4648282281281dbca281ac728f2f1ec
x86_64_v2 yggdrasil-0.4.9.2-1.el10_2.2.x86_64_v2.rpm 3ff2c82a6f0e353b9fb9632cff6a89d06e767ddcf7bc4089345e3ef8665f7ef1
x86_64_v2 yggdrasil-devel-0.4.9.2-1.el10_2.2.x86_64_v2.rpm f323a9d66af7dc52fd2450201ffeec1e3b8dd07c4f6e5575e046d8a6750bf4d8
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.