Important: yggdrasil security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:11413", "synopsis": "Important: yggdrasil security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for yggdrasil.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "yggdrasil is a system daemon that subscribes to topics on an MQTT broker and routes any data received on the topics to an appropriate child \"worker\" process, exchanging data with its worker processes through a D-Bus message broker.\n\nSecurity Fix(es):\n\n* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2445356", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", "description": ""}], "cves": [{"name": "CVE-2026-25679", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-1286"}], "references": [], "publishedAt": "2026-05-01T12:06:42.394267Z", "rpms": {"Rocky Linux 10": {"nvras": ["yggdrasil-debuginfo-0:0.4.8-4.el10_1.aarch64.rpm", "yggdrasil-debugsource-0:0.4.8-4.el10_1.aarch64.rpm", "yggdrasil-debugsource-0:0.4.8-4.el10_1.ppc64le.rpm", "yggdrasil-debugsource-0:0.4.8-4.el10_1.s390x.rpm", "yggdrasil-0:0.4.8-4.el10_1.aarch64.rpm", "yggdrasil-devel-0:0.4.8-4.el10_1.aarch64.rpm", "yggdrasil-debugsource-0:0.4.8-4.el10_1.x86_64.rpm", "yggdrasil-0:0.4.8-4.el10_1.src.rpm", "yggdrasil-devel-0:0.4.8-4.el10_1.x86_64.rpm", "yggdrasil-0:0.4.8-4.el10_1.x86_64.rpm","yggdrasil-devel-0:0.4.8-4.el10_1.ppc64le.rpm", "yggdrasil-debuginfo-0:0.4.8-4.el10_1.x86_64.rpm", "yggdrasil-debuginfo-0:0.4.8-4.el10_1.s390x.rpm", "yggdrasil-0:0.4.8-4.el10_1.ppc64le.rpm", "yggdrasil-0:0.4.8-4.el10_1.s390x.rpm", "yggdrasil-debuginfo-0:0.4.8-4.el10_1.ppc64le.rpm", "yggdrasil-devel-0:0.4.8-4.el10_1.s390x.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Yggdrasil security update available for Rocky Linux 10, addresses important flaw, recommended actions. Stay secure!. Rocky Linux 10 Yggdrasil security important update. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-17129 http://linux.oracle.com/errata/ELSA-2025-17129.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: bind-dyndb-ldap-11.6-6.module+el8.10.0+90553+1bd85afa.x86_64.rpm custodia-0.6.0-3.module+el8.9.0+90094+20819f5a.noarch.rpm ipa-client-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.x86_64.rpm ipa-client-common-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.noarch.rpm ipa-client-epn-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.x86_64.rpm ipa-client-samba-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.x86_64.rpm ipa-common-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.noarch.rpm ipa-healthcheck-0.12-6.module+el8.10.0+90676+16d53ab4.noarch.rpm ipa-healthcheck-core-0.12-6.module+el8.10.0+90676+16d53ab4.noarch.rpm ipa-python-compat-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.noarch.rpm ipa-selinux-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.noarch.rpm ipa-server-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.x86_64.rpm ipa-server-common-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.noarch.rpm ipa-server-dns-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.noarch.rpm ipa-server-trust-ad-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.x86_64.rpm opendnssec-2.1.7-2.module+el8.10.0+90553+1bd85afa.x86_64.rpm python3-custodia-0.6.0-3.module+el8.9.0+90094+20819f5a.noarch.rpm python3-ipaclient-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.noarch.rpm python3-ipalib-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.noarch.rpm python3-ipaserver-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.noarch.rpm python3-ipatests-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.noarch.rpm python3-jwcrypto-0.5.0-2.module+el8.10.0+90573+7d6bd8da.noarch.rpm python3-kdcproxy-0.4-5.module+el8.10.0+90553+1bd85afa.1.noarch.rpm python3-pyusb-1.0.0-9.1.module+el8.9.0+90094+20819f5a.noarch.rpm python3-qrcode-5.3-1.module+el8.10.0+90676+16d53ab4.noarch.rpm python3-qrcode-core-5.3-1.module+el8.10.0+90676+16d53ab4.noarch.rpm python3-yubico-1.3.2-9.1.module+el8.9.0+90094+20819f5a.noarch.rpm slapi-nis-0.60.0-4.module+el8.10.0+90297+bfe93ccc.x86_64.rpm softhsm-2.6.0-5.module+el8.9.0+90094+20819f5a.x86_64.rpm softhsm-devel-2.6.0-5.module+el8.9.0+90094+20819f5a.x86_64.rpm aarch64: bind-dyndb-ldap-11.6-6.module+el8.10.0+90553+1bd85afa.aarch64.rpm custodia-0.6.0-3.module+el8.9.0+90094+20819f5a.noarch.rpm ipa-client-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.aarch64.rpm ipa-client-common-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.noarch.rpm ipa-client-epn-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.aarch64.rpm ipa-client-samba-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.aarch64.rpm ipa-common-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.noarch.rpm ipa-healthcheck-0.12-6.module+el8.10.0+90676+16d53ab4.noarch.rpm ipa-healthcheck-core-0.12-6.module+el8.10.0+90676+16d53ab4.noarch.rpm ipa-python-compat-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.noarch.rpm ipa-selinux-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.noarch.rpm ipa-server-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.aarch64.rpm ipa-server-common-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.noarch.rpm ipa-server-dns-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.noarch.rpm ipa-server-trust-ad-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.aarch64.rpm opendnssec-2.1.7-2.module+el8.10.0+90553+1bd85afa.aarch64.rpm python3-custodia-0.6.0-3.module+el8.9.0+90094+20819f5a.noarch.rpm python3-ipaclient-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.noarch.rpm python3-ipalib-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.noarch.rpm python3-ipaserver-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.noarch.rpm python3-ipatests-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.noarch.rpm python3-jwcrypto-0.5.0-2.module+el8.10.0+90573+7d6bd8da.noarch.rpm python3-kdcproxy-0.4-5.module+el8.10.0+90553+1bd85afa.1.noarch.rpm python3-pyusb-1.0.0-9.1.module+el8.9.0+90094+20819f5a.noarch.rpm python3-qrcode-5.3-1.module+el8.10.0+90676+16d53ab4.noarch.rpm python3-qrcode-core-5.3-1.module+el8.10.0+90676+16d53ab4.noarch.rpm python3-yubico-1.3.2-9.1.module+el8.9.0+90094+20819f5a.noarch.rpm slapi-nis-0.60.0-4.module+el8.10.0+90297+bfe93ccc.aarch64.rpm softhsm-2.6.0-5.module+el8.9.0+90094+20819f5a.aarch64.rpm softhsm-devel-2.6.0-5.module+el8.9.0+90094+20819f5a.aarch64.rpm SRPMS: http://oss.oracle.com/ol8/SRPMS-updates/bind-dyndb-ldap-11.6-6.module+el8.10.0+90553+1bd85afa.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/custodia-0.6.0-3.module+el8.9.0+90094+20819f5a.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/ipa-4.9.13-20.0.1.module+el8.10.0+90676+16d53ab4.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/ipa-healthcheck-0.12-6.module+el8.10.0+90676+16d53ab4.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/opendnssec-2.1.7-2.module+el8.10.0+90553+1bd85afa.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/python-jwcrypto-0.5.0-2.module+el8.10.0+90573+7d6bd8da.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/python-kdcproxy-0.4-5.module+el8.10.0+90553+1bd85afa.1.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/python-qrcode-5.3-1.module+el8.10.0+90676+16d53ab4.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/python-yubico-1.3.2-9.1.module+el8.9.0+90094+20819f5a.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/pyusb-1.0.0-9.1.module+el8.9.0+90094+20819f5a.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/slapi-nis-0.60.0-4.module+el8.10.0+90297+bfe93ccc.src.rpm http://oss.oracle.com/ol8/SRPMS-updates/softhsm-2.6.0-5.module+el8.9.0+90094+20819f5a.src.rpm Related CVEs: CVE-2025-7493 Description of changes: bind-dyndb-ldap [11.6-6] - Fix rpminspect warnings Resolves: RHEL-22497 custodia ipa [4.9.13-20.0.1] - Set IPAPLATFORM=rhel when build on Oracle Linux [Orabug: 29516674] [4.9.13-20] - Refactor ipatests for unique krbcanonicalname Resolves: RHEL-110061 [4.9.13-19] - Enforce uniqueness across krbprincipalname and krbcanonicalname ipa-kdb: enforce PAC presence on TGT for TGS-REQ ipatests: extend test for unique krbcanonicalname Resolves: RHEL-110061 ipa-healthcheck opendnssec [2.1.7-2] - Don't creat /var/run/opendnssec directory - Resolves: RHEL-12163 python-jwcrypto python-kdcproxy [0.4-5.1] - Log KDC timeout only once per request Resolves:RHEL-68634 python-qrcode python-yubico pyusb slapi-nis softhsm _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.