[ALSA-2026:73766] Important: pki-core security update
Type:
security
Severity:
important
Release date:
2026-10-01
Description:
The Public Key Infrastructure (PKI) Core contains fundamental packages required by AlmaLinux Certificate System. Security Fix(es): * pki-core: Dogtag/PKI: certprofile-import allows code execution via unsanitized profile content (ExternalProcessConstraint) (CVE-2026-76561) * pki-core: Dogtag PKI v2 REST ACL filter's reverse-lexicographic tie-break lets a CA Agent invoke the admin-only raw profile creation endpoint (CVE-2026-80110) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 idm-pki-tools-11.7.1-2.el9_8.aarch64.rpm e9d0f73d1f59f447af4de48cf83e439d4ef18c2b71ea29cd23e046ec155086f1
noarch idm-pki-server-11.7.1-2.el9_8.noarch.rpm 0be7465bcb3362a3ee42f558a74c407c5e357a3cec76bf2d891b8f7b22b37fcc
noarch idm-pki-java-11.7.1-2.el9_8.noarch.rpm 45accff203deaf91b04d80b76a8b69fc0ed0167c3219777b49e3e560616c3e4f
noarch python3-idm-pki-11.7.1-2.el9_8.noarch.rpm 7cdb2b5d930010bbebf60d3b62fdedf7118fbb41a798b829b109192b8d60ae6a
noarch idm-pki-base-11.7.1-2.el9_8.noarch.rpm 7fe4d9e4ba29b64ee9004839fd331a3037c2fd71214a9750ccc0aa0a5f25cba1
noarch idm-pki-acme-11.7.1-2.el9_8.noarch.rpm ca1650891a908a6b38eef68f208682acdea4e0f58fe3e2d83478ccd526576ccb
noarch idm-pki-ca-11.7.1-2.el9_8.noarch.rpm d223ac6542cafc7b4197cb73101e27b427d0751ac102916e3043983e65773dce
noarch idm-pki-kra-11.7.1-2.el9_8.noarch.rpm ef33e6f4d5d2acd1e082dea0c53b585a59884c3eba548e0c3f7c5a2127db4669
ppc64le idm-pki-tools-11.7.1-2.el9_8.ppc64le.rpm c5a4aa50df033f9f4ff945713d525cd4fb46d8f9eb5da6b0fabb444dc8ff6245
s390x idm-pki-tools-11.7.1-2.el9_8.s390x.rpm a03d2adf31c776e03994f6f67771848156fb77d63a8d76d1cb2c48f08f6cc03d
x86_64 idm-pki-tools-11.7.1-2.el9_8.x86_64.rpm f3cf6842abfab225cfb11c98c5683157a4192e4d22da4899e11056515328eb8f
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.