{"id":"SUSE-SU-2026:3645-1","summary":"Security update for erlang","details":"This update for erlang fixes the following issues:\n\n- CVE-2026-28810: predictable DNS transaction IDs can cause DNS cache poisoning (bsc#1261726).\n- CVE-2026-42789: `public_key` application accepts non-CA certificates as intermediate issuers and this enables chain\n  forgery (bsc#1266449).\n- CVE-2026-42790: Name constraints and `Subject CommonName` fallback in TLS hostname verification allows for certificate\n  forgery by MITM attacker (bsc#1266466).\n- CVE-2026-42792: permanent `epmd` DoS via connection slot exhaustion due to improper handling of exceptional\n  conditions (bsc#1272908).\n- CVE-2026-47078: relative path traversal in `zip:unzip/zip:extract` via `check_dir_level` depth-counter bypass\n  (bsc#1272909).\n- CVE-2026-48855: SFTP `READLINK` response leaks absolute backend filesystem path when root is configured (bsc#1268139).\n- CVE-2026-48856: `httpc` leaks `Authorization` headers to cross-origin redirect targets (bsc#1268141).\n- CVE-2026-48858: server-side request forgery allows FTP bounce attacks and SSRF via an unvalidated `PASV` response IP\n  address (bsc#1268142).\n- CVE-2026-49759: unbounded stack buffer overflow in SCTP error cause parsing in `inet_drv` (bsc#1268163).\n- CVE-2026-49760: stack buffer overflow in `ei_s_print_term` at very large integer (bsc#1268164).\n- CVE-2026-53422: SFTP `REALPATH` path-existence oracle allows filesystem enumeration outside configured root\n  (bsc#1270245).\n- CVE-2026-54886: SSH SFTP server denial of service via extended channel data infinite loop (bsc#1270246).\n- CVE-2026-54887: use of default cryptographic key allows predictable DTLS cookie computation during the startup window\n  (bsc#1270247).\n- CVE-2026-54891: plaintext injection towards (D)TLS client during handshake (bsc#1270250).\n- CVE-2026-55737: heap pointer corruption via signed/unsigned mismatch in `LARGE_TUPLE_EXTP` decoding in `erts`\n  external term format decoder (bsc#1272910).\n- CVE-2026-55952: missing validation allows for DoS of the TLS-1.3 server when clients send a malformed `ClientHello`\n  with mismatched PSK identity and binder list lengths (bsc#1270258).\n- CVE-2026-55953: TLS 1.2 and DTLS clients accept unoffered anonymous cipher suites and allow for server authentication\n  bypass (bsc#1272911).\n- CVE-2026-58227: TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain\n  (bsc#1272913).\n- CVE-2026-59250: `megaco` flex scanner buffer overflow via oversized property parm name (bsc#1272914).\n","modified":"2026-08-21T09:15:25.790414546Z","published":"2026-08-18T18:14:04Z","related":["CVE-2026-28810","CVE-2026-42789","CVE-2026-42790","CVE-2026-42792","CVE-2026-47078","CVE-2026-48855","CVE-2026-48856","CVE-2026-48858","CVE-2026-49759","CVE-2026-49760","CVE-2026-53422","CVE-2026-54886","CVE-2026-54887","CVE-2026-54891","CVE-2026-55737","CVE-2026-55952","CVE-2026-55953","CVE-2026-58227","CVE-2026-59250"],"upstream":["CVE-2026-28810","CVE-2026-42789","CVE-2026-42790","CVE-2026-42792","CVE-2026-47078","CVE-2026-48855","CVE-2026-48856","CVE-2026-48858","CVE-2026-49759","CVE-2026-49760","CVE-2026-53422","CVE-2026-54886","CVE-2026-54887","CVE-2026-54891","CVE-2026-55737","CVE-2026-55952","CVE-2026-55953","CVE-2026-58227","CVE-2026-59250"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263645-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1261726"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266449"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266466"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268139"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268141"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268142"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268163"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268164"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270245"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270246"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270247"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270250"},{"type":"REPORT","url":"https://bugzilla.suse.com/1270258"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272908"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272909"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272910"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272911"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272913"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272914"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-28810"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42789"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42790"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42792"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-47078"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48855"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48856"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48858"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-49759"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-49760"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-53422"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-54886"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-54887"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-54891"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55737"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55952"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-55953"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58227"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-59250"}],"affected":[{"package":{"name":"erlang","ecosystem":"SUSE:Linux Enterprise Module for Server Applications 15 SP7","purl":"pkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"23.3.4.19-150300.3.39.1"}]}],"ecosystem_specific":{"binaries":[{"erlang-epmd":"23.3.4.19-150300.3.39.1","erlang":"23.3.4.19-150300.3.39.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3645-1.json"}},{"package":{"name":"erlang","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"23.3.4.19-150300.3.39.1"}]}],"ecosystem_specific":{"binaries":[{"erlang-epmd":"23.3.4.19-150300.3.39.1","erlang":"23.3.4.19-150300.3.39.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3645-1.json"}},{"package":{"name":"erlang","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"23.3.4.19-150300.3.39.1"}]}],"ecosystem_specific":{"binaries":[{"erlang":"23.3.4.19-150300.3.39.1","erlang-epmd":"23.3.4.19-150300.3.39.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3645-1.json"}},{"package":{"name":"erlang","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS","purl":"pkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"23.3.4.19-150300.3.39.1"}]}],"ecosystem_specific":{"binaries":[{"erlang":"23.3.4.19-150300.3.39.1","erlang-epmd":"23.3.4.19-150300.3.39.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3645-1.json"}},{"package":{"name":"erlang","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS","purl":"pkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"23.3.4.19-150300.3.39.1"}]}],"ecosystem_specific":{"binaries":[{"erlang-epmd":"23.3.4.19-150300.3.39.1","erlang":"23.3.4.19-150300.3.39.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3645-1.json"}},{"package":{"name":"erlang","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"23.3.4.19-150300.3.39.1"}]}],"ecosystem_specific":{"binaries":[{"erlang":"23.3.4.19-150300.3.39.1","erlang-epmd":"23.3.4.19-150300.3.39.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3645-1.json"}},{"package":{"name":"erlang","ecosystem":"SUSE:Linux Enterprise Server 15 SP5-LTSS","purl":"pkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"23.3.4.19-150300.3.39.1"}]}],"ecosystem_specific":{"binaries":[{"erlang-epmd":"23.3.4.19-150300.3.39.1","erlang":"23.3.4.19-150300.3.39.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3645-1.json"}},{"package":{"name":"erlang","ecosystem":"SUSE:Linux Enterprise Server 15 SP6-LTSS","purl":"pkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"23.3.4.19-150300.3.39.1"}]}],"ecosystem_specific":{"binaries":[{"erlang":"23.3.4.19-150300.3.39.1","erlang-epmd":"23.3.4.19-150300.3.39.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3645-1.json"}},{"package":{"name":"erlang","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"23.3.4.19-150300.3.39.1"}]}],"ecosystem_specific":{"binaries":[{"erlang":"23.3.4.19-150300.3.39.1","erlang-epmd":"23.3.4.19-150300.3.39.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3645-1.json"}},{"package":{"name":"erlang","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP5","purl":"pkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"23.3.4.19-150300.3.39.1"}]}],"ecosystem_specific":{"binaries":[{"erlang":"23.3.4.19-150300.3.39.1","erlang-epmd":"23.3.4.19-150300.3.39.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3645-1.json"}},{"package":{"name":"erlang","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP6","purl":"pkg:rpm/suse/erlang&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"23.3.4.19-150300.3.39.1"}]}],"ecosystem_specific":{"binaries":[{"erlang-epmd":"23.3.4.19-150300.3.39.1","erlang":"23.3.4.19-150300.3.39.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3645-1.json"}}],"schema_version":"1.9.0"}