Important: yggdrasil security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:11413", "synopsis": "Important: yggdrasil security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for yggdrasil.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "yggdrasil is a system daemon that subscribes to topics on an MQTT broker and routes any data received on the topics to an appropriate child \"worker\" process, exchanging data with its worker processes through a D-Bus message broker.\n\nSecurity Fix(es):\n\n* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2445356", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", "description": ""}], "cves": [{"name": "CVE-2026-25679", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-1286"}], "references": [], "publishedAt": "2026-05-01T12:06:42.394267Z", "rpms": {"Rocky Linux 10": {"nvras": ["yggdrasil-debuginfo-0:0.4.8-4.el10_1.aarch64.rpm", "yggdrasil-debugsource-0:0.4.8-4.el10_1.aarch64.rpm", "yggdrasil-debugsource-0:0.4.8-4.el10_1.ppc64le.rpm", "yggdrasil-debugsource-0:0.4.8-4.el10_1.s390x.rpm", "yggdrasil-0:0.4.8-4.el10_1.aarch64.rpm", "yggdrasil-devel-0:0.4.8-4.el10_1.aarch64.rpm", "yggdrasil-debugsource-0:0.4.8-4.el10_1.x86_64.rpm", "yggdrasil-0:0.4.8-4.el10_1.src.rpm", "yggdrasil-devel-0:0.4.8-4.el10_1.x86_64.rpm", "yggdrasil-0:0.4.8-4.el10_1.x86_64.rpm","yggdrasil-devel-0:0.4.8-4.el10_1.ppc64le.rpm", "yggdrasil-debuginfo-0:0.4.8-4.el10_1.x86_64.rpm", "yggdrasil-debuginfo-0:0.4.8-4.el10_1.s390x.rpm", "yggdrasil-0:0.4.8-4.el10_1.ppc64le.rpm", "yggdrasil-0:0.4.8-4.el10_1.s390x.rpm", "yggdrasil-debuginfo-0:0.4.8-4.el10_1.ppc64le.rpm", "yggdrasil-devel-0:0.4.8-4.el10_1.s390x.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Yggdrasil security update for Rocky Linux 10 addresses critical issues. Ensure your systems are secured promptly for optimal performance.. Rocky Linux Yggdrasil Update, Security Advisory Rocky Linux, Important Yggdrasil Security Fix. . Severity: Important. LinuxSecurity.com Team
Important: yggdrasil security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:11413", "synopsis": "Important: yggdrasil security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for yggdrasil.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "yggdrasil is a system daemon that subscribes to topics on an MQTT broker and routes any data received on the topics to an appropriate child \"worker\" process, exchanging data with its worker processes through a D-Bus message broker.\n\nSecurity Fix(es):\n\n* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2445356", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", "description": ""}], "cves": [{"name": "CVE-2026-25679", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-1286"}], "references": [], "publishedAt": "2026-05-01T12:06:42.394267Z", "rpms": {"Rocky Linux 10": {"nvras": ["yggdrasil-debuginfo-0:0.4.8-4.el10_1.aarch64.rpm", "yggdrasil-debugsource-0:0.4.8-4.el10_1.aarch64.rpm", "yggdrasil-debugsource-0:0.4.8-4.el10_1.ppc64le.rpm", "yggdrasil-debugsource-0:0.4.8-4.el10_1.s390x.rpm", "yggdrasil-0:0.4.8-4.el10_1.aarch64.rpm", "yggdrasil-devel-0:0.4.8-4.el10_1.aarch64.rpm", "yggdrasil-debugsource-0:0.4.8-4.el10_1.x86_64.rpm", "yggdrasil-0:0.4.8-4.el10_1.src.rpm", "yggdrasil-devel-0:0.4.8-4.el10_1.x86_64.rpm", "yggdrasil-0:0.4.8-4.el10_1.x86_64.rpm","yggdrasil-devel-0:0.4.8-4.el10_1.ppc64le.rpm", "yggdrasil-debuginfo-0:0.4.8-4.el10_1.x86_64.rpm", "yggdrasil-debuginfo-0:0.4.8-4.el10_1.s390x.rpm", "yggdrasil-0:0.4.8-4.el10_1.ppc64le.rpm", "yggdrasil-0:0.4.8-4.el10_1.s390x.rpm", "yggdrasil-debuginfo-0:0.4.8-4.el10_1.ppc64le.rpm", "yggdrasil-devel-0:0.4.8-4.el10_1.s390x.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important security update available for yggdrasil in Rocky Linux 10 addressing incorrect IPv6 host parsing issue.. yggdrasil security fix, Rocky Linux update, MQTT broker issue, network security. . Severity: Important. LinuxSecurity.com Team
Important: yggdrasil security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:5146", "synopsis": "Important: yggdrasil security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for yggdrasil.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "yggdrasil is a system daemon that subscribes to topics on an MQTT broker and routes any data received on the topics to an appropriate child \"worker\" process, exchanging data with its worker processes through a D-Bus message broker.\n\nSecurity Fix(es):\n\n* crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)\n\n* golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)\n\n* crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2434432", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", "description": ""}, {"ticket": "2437111", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", "description": ""}, {"ticket": "2418462", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2418462", "description": ""}], "cves": [{"name": "CVE-2025-61726", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-61726", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-770"}, {"name": "CVE-2025-61729", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-61729", "cvss3ScoringVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-1050"}, {"name": "CVE-2025-68121", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-68121", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "cvss3BaseScore": "7.4", "cwe": null}], "references": [], "publishedAt": "2026-03-27T12:07:50.770013Z", "rpms": {"Rocky Linux 10": {"nvras": ["yggdrasil-debuginfo-0:0.4.8-3.el10_1.aarch64.rpm", "yggdrasil-debugsource-0:0.4.8-3.el10_1.x86_64.rpm", "yggdrasil-devel-0:0.4.8-3.el10_1.s390x.rpm", "yggdrasil-debuginfo-0:0.4.8-3.el10_1.s390x.rpm", "yggdrasil-debugsource-0:0.4.8-3.el10_1.s390x.rpm", "yggdrasil-debugsource-0:0.4.8-3.el10_1.aarch64.rpm", "yggdrasil-devel-0:0.4.8-3.el10_1.x86_64.rpm", "yggdrasil-0:0.4.8-3.el10_1.s390x.rpm", "yggdrasil-0:0.4.8-3.el10_1.x86_64.rpm", "yggdrasil-devel-0:0.4.8-3.el10_1.aarch64.rpm", "yggdrasil-0:0.4.8-3.el10_1.src.rpm", "yggdrasil-debuginfo-0:0.4.8-3.el10_1.x86_64.rpm", "yggdrasil-0:0.4.8-3.el10_1.ppc64le.rpm", "yggdrasil-debuginfo-0:0.4.8-3.el10_1.ppc64le.rpm", "yggdrasil-debugsource-0:0.4.8-3.el10_1.ppc64le.rpm", "yggdrasil-devel-0:0.4.8-3.el10_1.ppc64le.rpm", "yggdrasil-0:0.4.8-3.el10_1.aarch64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Important yggdrasil security update for Rocky Linux 10 addresses Denial of Service and memory exhaustion risks.. yggdrasil update denial of service memory exhaustion Rocky Linux. . Severity: Important. LinuxSecurity.com Team
Important: yggdrasil security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:5146", "synopsis": "Important: yggdrasil security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for yggdrasil.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "yggdrasil is a system daemon that subscribes to topics on an MQTT broker and routes any data received on the topics to an appropriate child \"worker\" process, exchanging data with its worker processes through a D-Bus message broker.\n\nSecurity Fix(es):\n\n* crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)\n\n* golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)\n\n* crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2434432", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", "description": ""}, {"ticket": "2437111", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", "description": ""}, {"ticket": "2418462", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2418462", "description": ""}], "cves": [{"name": "CVE-2025-61726", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-61726", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-770"}, {"name": "CVE-2025-61729", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-61729", "cvss3ScoringVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-1050"}, {"name": "CVE-2025-68121", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-68121", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "cvss3BaseScore": "7.4", "cwe": null}], "references": [], "publishedAt": "2026-03-27T12:07:50.770013Z", "rpms": {"Rocky Linux 10": {"nvras": ["yggdrasil-debuginfo-0:0.4.8-3.el10_1.aarch64.rpm", "yggdrasil-debugsource-0:0.4.8-3.el10_1.x86_64.rpm", "yggdrasil-devel-0:0.4.8-3.el10_1.s390x.rpm", "yggdrasil-debuginfo-0:0.4.8-3.el10_1.s390x.rpm", "yggdrasil-debugsource-0:0.4.8-3.el10_1.s390x.rpm", "yggdrasil-debugsource-0:0.4.8-3.el10_1.aarch64.rpm", "yggdrasil-devel-0:0.4.8-3.el10_1.x86_64.rpm", "yggdrasil-0:0.4.8-3.el10_1.s390x.rpm", "yggdrasil-0:0.4.8-3.el10_1.x86_64.rpm", "yggdrasil-devel-0:0.4.8-3.el10_1.aarch64.rpm", "yggdrasil-0:0.4.8-3.el10_1.src.rpm", "yggdrasil-debuginfo-0:0.4.8-3.el10_1.x86_64.rpm", "yggdrasil-0:0.4.8-3.el10_1.ppc64le.rpm", "yggdrasil-debuginfo-0:0.4.8-3.el10_1.ppc64le.rpm", "yggdrasil-debugsource-0:0.4.8-3.el10_1.ppc64le.rpm", "yggdrasil-devel-0:0.4.8-3.el10_1.ppc64le.rpm", "yggdrasil-0:0.4.8-3.el10_1.aarch64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. The yggdrasil security update for Rocky Linux addresses important fixes for DoS and memory exhaustion issues.. Rocky Linux,yggdrasil security update,denial of service,memory exhaustion. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.