RHSA-2026:57126: Important: yggdrasil security update
Important: yggdrasil security update
Other sources
yggdrasil is a system daemon that subscribes to topics on an MQTT broker and routes any data received on the topics to an appropriate child "worker" process, exchanging data with its worker processes through a D-Bus message broker.Security Fix(es): crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/yggdrasilto a version that resolves this vulnerability.Fixed in 0.4.9.2-1.el10_2.2 - Upgrade
Upgrade
redhat/yggdrasil-debuginfoto a version that resolves this vulnerability.Fixed in 0.4.9.2-1.el10_2.2 - Upgrade
Upgrade
redhat/yggdrasil-debugsourceto a version that resolves this vulnerability.Fixed in 0.4.9.2-1.el10_2.2 - Upgrade
Upgrade
redhat/yggdrasil-examples-debuginfoto a version that resolves this vulnerability.Fixed in 0.4.9.2-1.el10_2.2 - Upgrade
Upgrade
redhat/yggdrasilto a version that resolves this vulnerability.Fixed in 0.4.9.2-1.el10_2.2.aa - Upgrade
Upgrade
redhat/yggdrasil-debuginfoto a version that resolves this vulnerability.Fixed in 0.4.9.2-1.el10_2.2.aa - Upgrade
Upgrade
redhat/yggdrasil-debugsourceto a version that resolves this vulnerability.Fixed in 0.4.9.2-1.el10_2.2.aa - Upgrade
Upgrade
redhat/yggdrasil-examples-debuginfoto a version that resolves this vulnerability.Fixed in 0.4.9.2-1.el10_2.2.aa - Upgrade
Upgrade
redhat/yggdrasil-develto a version that resolves this vulnerability.Fixed in 0.4.9.2-1.el10_2.2 - Upgrade
Upgrade
redhat/yggdrasil-develto a version that resolves this vulnerability.Fixed in 0.4.9.2-1.el10_2.2.aa
Event History
Frequently Asked Questions
Which systems are in scope for this update?
The advisory applies to listed Red Hat Enterprise Linux offerings for x86_64, IBM z Systems, and Power little endian, including certain Extended Update Support, Extended Life Cycle, and CodeReady Linux Builder channels.
What should teams do to determine whether they are affected?
Identify whether affected systems use the listed Red Hat product channels and check their installed yggdrasil package against the update provided by RHSA-2026:57126. The supplied data does not include affected or fixed package versions.
Is there a documented workaround if the update cannot be applied immediately?
No workaround or mitigation is provided in the supplied advisory data. Prioritize applying the Red Hat security update through the applicable supported channel.