Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2026-57126

Опубликовано: 19 авг. 2026
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2026-57126: yggdrasil security update (IMPORTANT)

[0.4.9.2-2]

  • Rebuild yggdrasil against updated golang

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

yggdrasil

0.4.9.2-1.el10_2.2

yggdrasil-devel

0.4.9.2-1.el10_2.2

Oracle Linux x86_64

yggdrasil

0.4.9.2-1.el10_2.2

yggdrasil-devel

0.4.9.2-1.el10_2.2

Связанные CVE

Связанные уязвимости

CVSS3: 8.2
ubuntu
5 месяцев назад

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 8.8
redhat
5 месяцев назад

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 8.2
nvd
5 месяцев назад

When verifying a certificate chain containing excluded DNS constraints, these constraints are not correctly applied to wildcard DNS SANs which use a different case than the constraint. This only affects validation of otherwise trusted certificate chains, issued by a root CA in the VerifyOptions.Roots CertPool, or in the system certificate pool.

CVSS3: 5.9
msrc
5 месяцев назад

Case-sensitive excludedSubtrees name constraints cause Auth Bypass in crypto/x509

CVSS3: 8.2
debian
5 месяцев назад

When verifying a certificate chain containing excluded DNS constraints ...