Description:
go-fdo-client is the device-side implementation of FIDO Device Onboard specification in Go. It provides an FDO client that interacts with FDO manufacturer and owner servers to perform device on-boarding.
Security Fix(es):
* crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810)
* encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
* net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
* crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
| Architecture |
Package |
Checksum |
| aarch64 |
go-fdo-client-1.0.0-4.el10_2.7.aarch64.rpm |
4924dd4a84e7431cd830f6e65c70bad37dff009a69cdb4cca86909f4ee969a7c |
| x86_64 |
go-fdo-client-1.0.0-4.el10_2.7.x86_64.rpm |
7928582ddb4a7ed969f44779c0be60496ff60d5d4fc69d55bb25e3ba01041abd |
| x86_64_v2 |
go-fdo-client-1.0.0-4.el10_2.7.x86_64_v2.rpm |
a0565631152a699ee8bac4e7c962dca6e655fbcb0abea6fdc41c00c43564b54f |