[ALSA-2026:62577] Important: go-fdo-client security update
Type:
security
Severity:
important
Release date:
2026-09-04
Description:
go-fdo-client is the device-side implementation of FIDO Device Onboard specification in Go. It provides an FDO client that interacts with FDO manufacturer and owner servers to perform device on-boarding. Security Fix(es): * crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 go-fdo-client-1.0.0-4.el10_2.7.aarch64.rpm 4924dd4a84e7431cd830f6e65c70bad37dff009a69cdb4cca86909f4ee969a7c
x86_64 go-fdo-client-1.0.0-4.el10_2.7.x86_64.rpm 7928582ddb4a7ed969f44779c0be60496ff60d5d4fc69d55bb25e3ba01041abd
x86_64_v2 go-fdo-client-1.0.0-4.el10_2.7.x86_64_v2.rpm a0565631152a699ee8bac4e7c962dca6e655fbcb0abea6fdc41c00c43564b54f
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.