Description:
HTTP reverse proxy, backed by IPP-over-USB connection to device. It enables
driverless support for USB devices capable of using IPP-over-USB protocol.
Security Fix(es):
* mime: golang: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504)
* encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)
* net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)
* net/[http:](http:) golang: Go net/[http:](http:) Unencrypted HTTP/2 connections vulnerable to Denial of Service (CVE-2026-56853)
* crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)
* encoding/xml: golang: Go: Denial of Service via XML decoding recursion depth issue (CVE-2026-56859)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
| Architecture |
Package |
Checksum |
| aarch64 |
ipp-usb-0.9.27-7.el10_2.3.aarch64.rpm |
9d24f8bb01144e65e82e32a078f6ea9b09bdcbaf8fe9da866ebcfa6ed19056e8 |
| ppc64le |
ipp-usb-0.9.27-7.el10_2.3.ppc64le.rpm |
a486852e8645bb3048978edede0993975200378e9ecdc65b9779aa6b599c729f |
| s390x |
ipp-usb-0.9.27-7.el10_2.3.s390x.rpm |
c80787f763462cdcd9daee3fc2f4880856b27caba56435f667f828e1bd1baa0f |
| x86_64 |
ipp-usb-0.9.27-7.el10_2.3.x86_64.rpm |
b1745b11d84bd36ac6522cc1225a4f5fad7cccf0d71681dbae418568142f1f36 |
| x86_64_v2 |
ipp-usb-0.9.27-7.el10_2.3.x86_64_v2.rpm |
a761a88724f2a8bcb27a7d9e964ce31af4008307809b16d011fcc03578fdb6f0 |