Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Important: yggdrasil security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:39573", "synopsis": "Important: yggdrasil security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for yggdrasil.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "yggdrasil is a system daemon that subscribes to topics on an MQTT broker and routes any data received on the topics to an appropriate child \"worker\" process, exchanging data with its worker processes through a D-Bus message broker.\n\nSecurity Fix(es):\n\n* net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811)\n\n* golang.org/x/net/idna: golang: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821)\n\n* crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2484207", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2484207", "description": ""}, {"ticket": "2480756", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2480756", "description": ""}, {"ticket": "2467822", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2467822", "description": ""}], "cves": [{"name": "CVE-2026-27145", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-27145", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-606"}, {"name": "CVE-2026-33811", "sourceBy": "MITRE","sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33811", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-1341"}, {"name": "CVE-2026-39821", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-39821", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N", "cvss3BaseScore": "8.2", "cwe": "CWE-1289"}], "references": [], "publishedAt": "2026-07-15T12:06:01.640959Z", "rpms": {"Rocky Linux 10": {"nvras": ["yggdrasil-0:0.4.9.2-1.el10_2.ppc64le.rpm", "yggdrasil-0:0.4.9.2-1.el10_2.x86_64.rpm", "yggdrasil-debugsource-0:0.4.9.2-1.el10_2.x86_64.rpm", "yggdrasil-0:0.4.9.2-1.el10_2.s390x.rpm", "yggdrasil-debugsource-0:0.4.9.2-1.el10_2.aarch64.rpm", "yggdrasil-devel-0:0.4.9.2-1.el10_2.ppc64le.rpm", "yggdrasil-debuginfo-0:0.4.9.2-1.el10_2.aarch64.rpm", "yggdrasil-devel-0:0.4.9.2-1.el10_2.s390x.rpm", "yggdrasil-devel-0:0.4.9.2-1.el10_2.aarch64.rpm", "yggdrasil-debuginfo-0:0.4.9.2-1.el10_2.ppc64le.rpm", "yggdrasil-debuginfo-0:0.4.9.2-1.el10_2.s390x.rpm", "yggdrasil-debuginfo-0:0.4.9.2-1.el10_2.x86_64.rpm", "yggdrasil-0:0.4.9.2-1.el10_2.src.rpm", "yggdrasil-devel-0:0.4.9.2-1.el10_2.x86_64.rpm", "yggdrasil-debugsource-0:0.4.9.2-1.el10_2.s390x.rpm", "yggdrasil-debugsource-0:0.4.9.2-1.el10_2.ppc64le.rpm", "yggdrasil-0:0.4.9.2-1.el10_2.aarch64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A critical yggdrasil security update for Rocky Linux 10 addressing multiple issues with denial of service and privilege escalation vulnerabilities.. Rocky Linux, Yggdrasil, security update, denial of service, privilege escalation. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-17075 http://linux.oracle.com/errata/ELSA-2026-17075.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: yggdrasil-0.4.8-5.el10_1.x86_64.rpm yggdrasil-devel-0.4.8-5.el10_1.x86_64.rpm aarch64: yggdrasil-0.4.8-5.el10_1.aarch64.rpm yggdrasil-devel-0.4.8-5.el10_1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/yggdrasil-0.4.8-5.el10_1.src.rpm Related CVEs: CVE-2026-32282 CVE-2026-32283 Description of changes: [0.4.8-5] - Bump release for rebuild _______________________________________________ El-errata mailing list
Important: yggdrasil security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:11413", "synopsis": "Important: yggdrasil security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for yggdrasil.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "yggdrasil is a system daemon that subscribes to topics on an MQTT broker and routes any data received on the topics to an appropriate child \"worker\" process, exchanging data with its worker processes through a D-Bus message broker.\n\nSecurity Fix(es):\n\n* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2445356", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2445356", "description": ""}], "cves": [{"name": "CVE-2026-25679", "sourceBy": "MITRE", "sourceLink": "https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25679", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-1286"}], "references": [], "publishedAt": "2026-05-01T12:06:42.394267Z", "rpms": {"Rocky Linux 10": {"nvras": ["yggdrasil-debuginfo-0:0.4.8-4.el10_1.aarch64.rpm", "yggdrasil-debugsource-0:0.4.8-4.el10_1.aarch64.rpm", "yggdrasil-debugsource-0:0.4.8-4.el10_1.ppc64le.rpm", "yggdrasil-debugsource-0:0.4.8-4.el10_1.s390x.rpm", "yggdrasil-0:0.4.8-4.el10_1.aarch64.rpm", "yggdrasil-devel-0:0.4.8-4.el10_1.aarch64.rpm", "yggdrasil-debugsource-0:0.4.8-4.el10_1.x86_64.rpm", "yggdrasil-0:0.4.8-4.el10_1.src.rpm", "yggdrasil-devel-0:0.4.8-4.el10_1.x86_64.rpm", "yggdrasil-0:0.4.8-4.el10_1.x86_64.rpm","yggdrasil-devel-0:0.4.8-4.el10_1.ppc64le.rpm", "yggdrasil-debuginfo-0:0.4.8-4.el10_1.x86_64.rpm", "yggdrasil-debuginfo-0:0.4.8-4.el10_1.s390x.rpm", "yggdrasil-0:0.4.8-4.el10_1.ppc64le.rpm", "yggdrasil-0:0.4.8-4.el10_1.s390x.rpm", "yggdrasil-debuginfo-0:0.4.8-4.el10_1.ppc64le.rpm", "yggdrasil-devel-0:0.4.8-4.el10_1.s390x.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. yggdrasil update addresses critical security flaws in Rocky Linux 10, protecting against network vulnerabilities. Learn more.. yggdrasil security update, Rocky Linux security, important security fixes, network vulnerabilities. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-11413 http://linux.oracle.com/errata/ELSA-2026-11413.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: yggdrasil-0.4.8-4.el10_1.x86_64.rpm yggdrasil-devel-0.4.8-4.el10_1.x86_64.rpm aarch64: yggdrasil-0.4.8-4.el10_1.aarch64.rpm yggdrasil-devel-0.4.8-4.el10_1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/yggdrasil-0.4.8-4.el10_1.src.rpm Related CVEs: CVE-2026-25679 Description of changes: [0.4.8-4] - Bump release for rebuild _______________________________________________ El-errata mailing list
Important: yggdrasil security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:5146", "synopsis": "Important: yggdrasil security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for yggdrasil.\nThis update affects Rocky Linux 10.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "yggdrasil is a system daemon that subscribes to topics on an MQTT broker and routes any data received on the topics to an appropriate child \"worker\" process, exchanging data with its worker processes through a D-Bus message broker.\n\nSecurity Fix(es):\n\n* crypto/x509: golang: Denial of Service due to excessive resource consumption via crafted certificate (CVE-2025-61729)\n\n* golang: net/url: Memory exhaustion in query parameter parsing in net/url (CVE-2025-61726)\n\n* crypto/tls: Unexpected session resumption in crypto/tls (CVE-2025-68121)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 10"], "fixes": [{"ticket": "2434432", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2434432", "description": ""}, {"ticket": "2437111", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2437111", "description": ""}, {"ticket": "2418462", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2418462", "description": ""}], "cves": [{"name": "CVE-2025-61726", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-61726", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-770"}, {"name": "CVE-2025-61729", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-61729", "cvss3ScoringVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-1050"}, {"name": "CVE-2025-68121", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-68121", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N", "cvss3BaseScore": "7.4", "cwe": null}], "references": [], "publishedAt": "2026-03-27T12:07:50.770013Z", "rpms": {"Rocky Linux 10": {"nvras": ["yggdrasil-debuginfo-0:0.4.8-3.el10_1.aarch64.rpm", "yggdrasil-debugsource-0:0.4.8-3.el10_1.x86_64.rpm", "yggdrasil-devel-0:0.4.8-3.el10_1.s390x.rpm", "yggdrasil-debuginfo-0:0.4.8-3.el10_1.s390x.rpm", "yggdrasil-debugsource-0:0.4.8-3.el10_1.s390x.rpm", "yggdrasil-debugsource-0:0.4.8-3.el10_1.aarch64.rpm", "yggdrasil-devel-0:0.4.8-3.el10_1.x86_64.rpm", "yggdrasil-0:0.4.8-3.el10_1.s390x.rpm", "yggdrasil-0:0.4.8-3.el10_1.x86_64.rpm", "yggdrasil-devel-0:0.4.8-3.el10_1.aarch64.rpm", "yggdrasil-0:0.4.8-3.el10_1.src.rpm", "yggdrasil-debuginfo-0:0.4.8-3.el10_1.x86_64.rpm", "yggdrasil-0:0.4.8-3.el10_1.ppc64le.rpm", "yggdrasil-debuginfo-0:0.4.8-3.el10_1.ppc64le.rpm", "yggdrasil-debugsource-0:0.4.8-3.el10_1.ppc64le.rpm", "yggdrasil-devel-0:0.4.8-3.el10_1.ppc64le.rpm", "yggdrasil-0:0.4.8-3.el10_1.aarch64.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. An important security update for yggdrasil on Rocky Linux addresses critical vulnerabilities and their impacts.. Rocky Linux yggdrasil update important vulnerabilities. . Severity: Important. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:. Oracle Linux Security Advisory ELSA-2026-5146 http://linux.oracle.com/errata/ELSA-2026-5146.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: yggdrasil-0.4.8-3.el10_1.x86_64.rpm yggdrasil-devel-0.4.8-3.el10_1.x86_64.rpm aarch64: yggdrasil-0.4.8-3.el10_1.aarch64.rpm yggdrasil-devel-0.4.8-3.el10_1.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/yggdrasil-0.4.8-3.el10_1.src.rpm Related CVEs: CVE-2025-61726 CVE-2025-61729 CVE-2025-68121 Description of changes: [0.4.8-3] - Bump release for rebuild _______________________________________________ El-errata mailing list
The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2025-7592 http://linux.oracle.com/errata/ELSA-2025-7592.html The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network: x86_64: yggdrasil-0.4.5-3.el10_0.x86_64.rpm yggdrasil-devel-0.4.5-3.el10_0.x86_64.rpm aarch64: yggdrasil-0.4.5-3.el10_0.aarch64.rpm yggdrasil-devel-0.4.5-3.el10_0.aarch64.rpm SRPMS: http://oss.oracle.com/ol10/SRPMS-updates/yggdrasil-0.4.5-3.el10_0.src.rpm Related CVEs: CVE-2024-45336 CVE-2025-3931 Description of changes: [0.4.5-3] - Fix CVE-2025-3931 _______________________________________________ El-errata mailing list
Get the latest Linux and open source security news straight to your inbox.