[Apollo] Advisories Statistics light light Login

RLSA-2026:62577

Security Mirrored from RHSA-2026:62577
Issued at: 2026-09-03
Updated at: 2026-09-04

Advisory content derived from Red Hat RHSA-2026:62577, © Red Hat, Inc., used under CC BY 4.0, with modifications.

Synopsis

Important: go-fdo-client security update



Description

go-fdo-client is the device-side implementation of FIDO Device Onboard specification in Go. It provides an FDO client that interacts with FDO manufacturer and owner servers to perform device on-boarding.

Security Fix(es):

* crypto/x509: golang: Go crypto/x509: Certificate validation bypass due to incorrect DNS constraint application (CVE-2026-33810)

* encoding/asn1: golang: Go encoding/asn1: Denial of Service via excessive recursion in Unmarshal (CVE-2026-33818)

* net/url: golang: golang net/url: Denial of Service from quadratic complexity in path resolution (CVE-2026-56860)

* crypto/tls: golang: Golang crypto/tls: Denial of Service via indefinite KeyUpdate messages (CVE-2026-56862)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.



Affected products

Rocky Linux 10 aarch64 Rocky Linux 10 riscv64 Rocky Linux 10 x86_64

Fixes

2515820 2456335 2515815 2515839

CVEs

CVE-2026-33810 CVE-2026-33818 CVE-2026-56860 CVE-2026-56862

Affected packages

Rocky Linux 10 x86_64 - AppStream

go-fdo-client-debugsource-0:1.0.0-4.el10_2.7.x86_64.rpm go-fdo-client-0:1.0.0-4.el10_2.7.x86_64.rpm go-fdo-client-debuginfo-0:1.0.0-4.el10_2.7.x86_64.rpm go-fdo-client-0:1.0.0-4.el10_2.7.src.rpm

Rocky Linux 10 aarch64 - AppStream

go-fdo-client-debugsource-0:1.0.0-4.el10_2.7.aarch64.rpm go-fdo-client-0:1.0.0-4.el10_2.7.aarch64.rpm go-fdo-client-debuginfo-0:1.0.0-4.el10_2.7.aarch64.rpm go-fdo-client-0:1.0.0-4.el10_2.7.src.rpm

Rocky Linux 10 riscv64 - AppStream

go-fdo-client-0:1.0.0-4.el10_2.7.src.rpm