Affected versions: Rocky Linux 10

📖 ~4 min read  •  Source: Rocky Linux RXSA RLSA-2026:11412

Related CVEs: CVE-2026-25679 CVE-2025-61726

Upstream summary: yggdrasil-worker-package-manager is a simple package manager yggd worker. It knows how to install and remove packages, add, remove, enable and disable repositories, and does rudimentary detection of the host it is running on to guess the package manager to use. It only installs packages that match one of the provided allow-pattern regular expressions.

Security Fix(es):

* net/url: Incorrect parsing of IPv6 host literals in net/url (CVE-2026-25679)

For more details about the

Table of contents
  1. Symptom & Impact
  2. Environment & Reproduction
  3. Root Cause Analysis
  4. Quick Triage
  5. Step-by-Step Diagnosis
  6. Solution – Primary Fix
  7. Solution – Alternative Approaches
  8. Verification & Acceptance Criteria
  9. Rollback Plan
  10. Prevention & Hardening
  11. Related Errors & Cross-Refs
  12. References & Further Reading

Symptom & Impact

On Rocky Linux 10 hosts running yggdrasil-worker-package-manager, the vulnerable code is started by something else – a web or application server, or an on-demand supervisor such as inetd, xinetd or a systemd socket unit – rather than by a service of its own. Patching replaces the files on disk immediately, but a long-running parent that has already loaded them (PHP-FPM workers, an application server, a persistent worker pool) keeps serving the old code until it is recycled. Connection-per-process supervisors pick the fix up on the next connection, so the exposure window differs sharply between the two and is worth confirming rather than assuming. yggdrasil-worker-package-manager is started by a hosting server or an on-demand supervisor rather than by a unit of its own, so restart whatever launches it – not yggdrasil-worker-package-manager.

Environment & Reproduction

Reproduction targets Rocky Linux 10. Confirm release and the installed package:

cat /etc/rocky-release
cat /etc/os-release
rpm -q yggdrasil-worker-package-manager
dnf info yggdrasil-worker-package-manager | head -20

Exercise the workload that uses yggdrasil-worker-package-manager while collecting:

sudo needs-restarting -u  # --useronly: restrict to the invoking user's processes (useful on shared/app hosts)
sudo lsof -n +L1  # link count < 1 = file deleted but still open/mmap'd; this is the ground truth after an RPM replaces a .so (package: lsof)
sudo lsof -n +L1 2>/dev/null | awk 'NR>1 {print $1, $2}' | sort -u  # condensed COMMAND + PID list of every process still running old code
sudo journalctl -xe --no-pager | tail -200
sudo tail -200 /var/log/dnf.log
sudo tail -200 /var/log/audit/audit.log
# For an evidence bundle bundle with sosreport:
sudo sosreport --batch

Root Cause Analysis

Root cause is documented in Rocky Linux RXSA RLSA-2026:11412. Rocky Linux / Red Hat maintainers shipped fixes in the corresponding yggdrasil-worker-package-manager update for Rocky Linux 10; running an outdated build leaves the host exposed to the failure modes described in the advisory. Correlate dnf history with system logs:

sudo dnf history | head
sudo dnf history list yggdrasil-worker-package-manager
sudo dnf history info <id>
sudo ausearch -m AVC,USER_AVC -ts today | tail -100
cat /proc/sys/kernel/tainted   # non-zero = tainted kernel / out-of-tree modules

Quick Triage

Run these on Rocky Linux 10 to capture the current state of yggdrasil-worker-package-manager:

rpm -q yggdrasil-worker-package-manager                              # installed NVR
rpm -V yggdrasil-worker-package-manager                              # verify shipped files
sudo dnf check-update --security
sudo dnf updateinfo list cves
systemctl --failed --no-pager
sudo firewall-cmd --list-all
getenforce && sestatus
dnf repoquery -l yggdrasil-worker-package-manager 2>/dev/null | grep -E '/lib/systemd/system/.*\.(service|socket|timer)$'  # same check WITHOUT installing (EL7/Amazon Linux 2: yum install yum-utils, then: repoquery -l yggdrasil-worker-package-manager)
systemctl show --no-pager -p Type,RemainAfterExit <UNIT>  # Type=oneshot (often paired with a .timer) means a one-shot job, NOT a daemon -- do not 'restart' it, let the timer fire

Step-by-Step Diagnosis

  1. List failed systemd units.

    systemctl --failed --no-pager
  2. Tail the journal for yggdrasil-worker-package-manager and the system bus.

    sudo journalctl -xe -f --no-pager
  3. Inspect firewall posture.

    sudo firewall-cmd --list-all-zones --permanent
    sudo nft list ruleset 2>/dev/null | head -50
  4. Surface SELinux denials and author a local policy module if needed.

    sudo ausearch -m AVC,USER_AVC -ts today
    sudo ausearch -m AVC -ts today | audit2allow -a -M /tmp/local-fix
    sudo semodule -i /tmp/local-fix.pp
  5. Verify yggdrasil-worker-package-manager integrity and reinstall if anything is altered.

    sudo rpm -V yggdrasil-worker-package-manager
    sudo dnf reinstall yggdrasil-worker-package-manager
  6. Correlate findings with /var/log/dnf.log, dnf history, and Rocky Linux RXSA RLSA-2026:11412 to pin the change that introduced the regression.

Solution – Primary Fix

Apply the corrective dnf transaction referenced by Rocky Linux RXSA RLSA-2026:11412, then reload affected systemd units:

sudo dnf -y makecache
sudo dnf -y upgrade --security              # apply ALL security errata (recommended)
# Or target a single package:
sudo dnf -y upgrade yggdrasil-worker-package-manager
sudo systemctl daemon-reload
# Unit name may differ from pkg name; check first:
sudo needs-restarting -s | sort -u  # STEP 1: read the list before acting. dbus.service, systemd-logind.service and PID 1 must NOT be blind-restarted on a live host -- those mean 'reboot'
sudo systemctl daemon-reload  # STEP 3: pick up any unit files the update rewrote
sudo systemctl restart <UNIT> && sudo systemctl is-active <UNIT> && sudo systemctl status --no-pager --full <UNIT>  # single-unit path, with an immediate health check
systemctl --user list-units --type=service --no-pager  # desktop/session and per-user services are a separate manager; restart them with: systemctl --user restart <UNIT>
rpm -q yggdrasil-worker-package-manager                                # confirm new NVR

For kernel / glibc / systemd / openssl advisories a reboot is required (or kpatch where licensed):

sudo needs-restarting -r                    # report whether reboot needed
sudo systemctl reboot                       # or: sudo shutdown -r now
# kpatch (Red Hat / Oracle) avoids reboot for many kernel CVEs:
sudo dnf install -y kpatch kpatch-dnf
sudo dnf kpatch auto                        # enable auto-patching
sudo kpatch list

Need help rolling this patch across a Rocky Linux fleet? Our IT Solutions & Services team manages Rocky / RHEL patch windows with Pulp / Foreman / Spacewalk plus kpatch. Get in touch for a free consultation.

Solution – Alternative Approaches

If the primary patch is not viable, choose from these:

  • Roll back the offending dnf transaction:

    sudo dnf history list | head
    sudo dnf history info <id>
    sudo dnf history undo <id>
  • Version-lock the package so dnf cannot upgrade it:

    sudo dnf install -y python3-dnf-plugin-versionlock
    sudo dnf versionlock add yggdrasil-worker-package-manager
    sudo dnf versionlock list
    sudo dnf versionlock delete yggdrasil-worker-package-manager      # remove the lock
  • Install an older NVR if a regression is suspected:

    dnf --showduplicates list yggdrasil-worker-package-manager | tac | head
    sudo dnf install -y --allowerasing yggdrasil-worker-package-manager-<older-NVR>
  • Switch SELinux to permissive briefly to confirm policy is the cause, then re-enforce:

    sudo setenforce 0
    # reproduce, capture denials, author a custom module:
    sudo ausearch -m AVC -ts recent | audit2allow -a -M mylocal
    sudo semodule -i mylocal.pp
    sudo setenforce 1
  • Take an LVM snapshot before kernel / glibc upgrades for fast rollback:

    sudo lvs
    sudo lvcreate -s -n preupgrade -L 4G /dev/<vg>/<lv>
    # revert later via:
    sudo lvconvert --merge /dev/<vg>/preupgrade && sudo systemctl reboot
  • Where kpatch is licensed, apply kernel fixes without reboot:

    sudo kpatch list
    sudo kpatch load /usr/lib/modules/$(uname -r)/extra/kpatch/*.ko

Verification & Acceptance Criteria

All of these should pass after the fix:

rpm -q yggdrasil-worker-package-manager                                            # expected fixed NVR
sudo dnf updateinfo list cves --installed               # CVEs above no longer listed
sudo firewall-cmd --list-services
getenforce
sudo needs-restarting -r

The conditions described in the advisory must no longer be reported for yggdrasil-worker-package-manager across two consecutive runs.

Rollback Plan

Capture state before any change:

rpm -qa > /root/rpm-pre.txt
sudo dnf history list > /root/dnf-history-pre.txt
# Optional LVM snapshot of the root LV:
sudo lvcreate -s -n preupgrade -L 4G /dev/<vg>/<lv>

To revert if the patch is bad:

sudo dnf history undo <id>
# Or downgrade just the package:
sudo dnf install -y --allowerasing yggdrasil-worker-package-manager-<older-NVR>
sudo systemctl daemon-reload
# Or merge the LVM snapshot and reboot:
sudo lvconvert --merge /dev/<vg>/preupgrade && sudo systemctl reboot
# Custom SELinux policy cleanup:
sudo semodule -r mylocal

Prevention & Hardening

Reduce the chance of this recurring on Rocky Linux 10:

  • Enable automatic security patching:

    sudo dnf install -y dnf-automatic
    sudo sed -i 's/^upgrade_type.*/upgrade_type = security/' /etc/dnf/automatic.conf
    sudo sed -i 's/^apply_updates.*/apply_updates = yes/' /etc/dnf/automatic.conf
    sudo systemctl enable --now dnf-automatic.timer
  • Subscribe to rocky-announce and watch Red Hat security updates for upstream changes.

  • Mirror through a local Pulp / Foreman / Spacewalk-style repo for controlled rollouts:

    sudo dnf install -y dnf-utils createrepo_c
    sudo reposync --download-metadata --downloadcomps -p /srv/mirror -- repoid=baseos
    sudo createrepo_c /srv/mirror/baseos
  • Version-lock sensitive packages so they cannot be auto-upgraded:

    sudo dnf install -y python3-dnf-plugin-versionlock
    sudo dnf versionlock add yggdrasil-worker-package-manager
  • Monitor file integrity with AIDE:

    sudo dnf install -y aide
    sudo aide --init && sudo mv /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gz
    sudo aide --check
  • Enable kpatch so kernel CVEs can be remediated without reboot:

    sudo dnf install -y kpatch kpatch-dnf
    sudo dnf kpatch auto
    sudo kpatch list
  • Keep SELinux in enforcing mode and review custom modules in /etc/selinux/targeted/ after every package upgrade.

  • Apply CIS Rocky Linux 10 Benchmark hardening and remove unused packages.

Issues that commonly surface alongside a yggdrasil-worker-package-manager update: dnf lock contention, systemd unit ordering cycles, SELinux AVC bursts, firewalld zone drift, and kernel taint flags. Useful triage:

sudo dnf check
systemd-analyze critical-chain
sudo ausearch -m AVC -ts today | tail
sudo firewall-cmd --get-active-zones
cat /proc/sys/kernel/tainted
sudo needs-restarting -r

View all rocky-linux-10 tutorials on the Tutorials Hub →

Browse all common problems & solutions on the Tutorials Hub.

References & Further Reading

Primary reference: Rocky Linux RXSA RLSA-2026:11412. Manual pages useful on Rocky Linux 10:

man dnf
man dnf.conf
man systemctl
man journalctl
man firewall-cmd
man semanage
man audit2allow
man kpatch
man sosreport

Other resources: docs.rockylinux.org, Red Hat CVE database, Rocky Linux errata, and per-package notes in /usr/share/doc/yggdrasil-worker-package-manager/ for components implicated in this advisory.


View all Rocky Linux 10 tutorials on the Tutorials Hub →