[ALSA-2026:62578] Important: go-fdo-server security update
Type:
security
Severity:
important
Release date:
2026-09-03
Description:
This package provides a server-side implementation of the FIDO Device Onboard (FDO) specification, written in Go. FDO is an open standard for the late binding of device credentials, allowing for automated and secure on-boarding of devices when they are first powered on in their final location. Security Fix(es): * crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 go-fdo-server-1.0.1-2.el10_2.4.aarch64.rpm 3fd37c6ce57f687d65f8c5afbf821e09b7239db12c17992ffb04dc3ab7ec8621
noarch go-fdo-server-rendezvous-1.0.1-2.el10_2.4.noarch.rpm 0211aa299091abf4cfdbbe76f87520827c571e8db4a3770fdd0349a146e1d8c0
noarch go-fdo-server-manufacturer-1.0.1-2.el10_2.4.noarch.rpm 84881985faeb5b98d8a5aa9bcdf5c151015a891734684a6dfae3071d412b6e96
noarch go-fdo-server-owner-1.0.1-2.el10_2.4.noarch.rpm df71d99ab263c33a04002cecffd3691380cb99ec2d02cac000f9c35a6af35a83
x86_64 go-fdo-server-1.0.1-2.el10_2.4.x86_64.rpm fe2a71a6200f1f679ee9f5e7ce34258fc78661c9fe3c625d9ade601bdf2e5c80
x86_64_v2 go-fdo-server-1.0.1-2.el10_2.4.x86_64_v2.rpm 129618859d7e7e51555f1114292207f6bbb9f12aee014d76dedc91de3ddea775
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.