[ALSA-2026:62631] Important: golang-github-openprinting-ipp-usb security update
Type:
security
Severity:
important
Release date:
2026-09-03
Description:
HTTP reverse proxy, backed by IPP-over-USB connection to device. It enables driverless support for USB devices capable of using IPP-over-USB protocol. Security Fix(es): * mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) * encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818) * net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860) * net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853) * crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862) * encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 ipp-usb-0.9.27-7.el10_2.3.aarch64.rpm 9d24f8bb01144e65e82e32a078f6ea9b09bdcbaf8fe9da866ebcfa6ed19056e8
ppc64le ipp-usb-0.9.27-7.el10_2.3.ppc64le.rpm a486852e8645bb3048978edede0993975200378e9ecdc65b9779aa6b599c729f
s390x ipp-usb-0.9.27-7.el10_2.3.s390x.rpm c80787f763462cdcd9daee3fc2f4880856b27caba56435f667f828e1bd1baa0f
x86_64 ipp-usb-0.9.27-7.el10_2.3.x86_64.rpm b1745b11d84bd36ac6522cc1225a4f5fad7cccf0d71681dbae418568142f1f36
x86_64_v2 ipp-usb-0.9.27-7.el10_2.3.x86_64_v2.rpm a761a88724f2a8bcb27a7d9e964ce31af4008307809b16d011fcc03578fdb6f0
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.