SUSE-SU-2026:3579-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263579-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3579-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:3579-1
Upstream
CVE (22)
Related
Published
2026-08-11T14:05:54Z
Modified
2026-08-12T10:45:05Z
Summary
Security update for erlang26
Details

This update for erlang26 fixes the following issues:

  • CVE-2026-28810: predictable DNS transaction IDs can cause DNS cache poisoning (bsc#1261726).
  • CVE-2026-42789: public_key application accepts non-CA certificates as intermediate issuers and this enables chain forgery (bsc#1266449).
  • CVE-2026-42790: Name constraints and Subject CommonName fallback in TLS hostname verification allows for certificate forgery by MITM attacker (bsc#1266466).
  • CVE-2026-42792: permanent epmd DoS via connection slot exhaustion due to improper handling of exceptional conditions (bsc#1272908).
  • CVE-2026-47078: relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass (bsc#1272909).
  • CVE-2026-48855: SFTP READLINK response leaks absolute backend filesystem path when root is configured (bsc#1268139).
  • CVE-2026-48856: httpc leaks Authorization headers to cross-origin redirect targets (bsc#1268141).
  • CVE-2026-48858: server-side request forgery allows FTP bounce attacks and SSRF via an unvalidated PASV response IP address (bsc#1268142).
  • CVE-2026-48860: ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-over-TLS LAN allowlist (bsc#1268146).
  • CVE-2026-49759: unbounded stack buffer overflow in SCTP error cause parsing in inet_drv (bsc#1268163).
  • CVE-2026-49760: stack buffer overflow in ei_s_print_term at very large integer (bsc#1268164).
  • CVE-2026-53422: SFTP REALPATH path-existence oracle allows filesystem enumeration outside configured root (bsc#1270245).
  • CVE-2026-54886: SSH SFTP server denial of service via extended channel data infinite loop (bsc#1270246).
  • CVE-2026-54887: use of default cryptographic key allows predictable DTLS cookie computation during the startup window (bsc#1270247).
  • CVE-2026-54891: plaintext injection towards (D)TLS client during handshake (bsc#1270250).
  • CVE-2026-55737: heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXTP decoding in erts external term format decoder (bsc#1272910).
  • CVE-2026-55950: time-of-check time-of-use race condition allows an unauthenticated remote attacker to crash all active DTLS sessions on a listener (bsc#1270253).
  • CVE-2026-55952: missing validation allows for DoS of the TLS-1.3 server when clients send a malformed ClientHello with mismatched PSK identity and binder list lengths (bsc#1270258).
  • CVE-2026-55953: TLS 1.2 and DTLS clients accept unoffered anonymous cipher suites and allow for server authentication bypass (bsc#1272911).
  • CVE-2026-58227: TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain (bsc#1272913).
  • CVE-2026-59250: megaco flex scanner buffer overflow via oversized property parm name (bsc#1272914).
  • CVE-2026-59251: denial of service via exponential certificate policy tree growth in path validation (bsc#1272915).
References

Affected packages

SUSE:Linux Enterprise Module for Server Applications 15 SP7
erlang26

Package

Name
erlang26
Purl
pkg:rpm/suse/erlang26&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Server%20Applications%2015%20SP7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
26.2.1-150300.7.28.1

Ecosystem specific

{
    "binaries":  [
        {
            "erlang26":  "26.2.1-150300.7.28.1",
            "erlang26-epmd":  "26.2.1-150300.7.28.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3579-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
erlang26

Package

Name
erlang26
Purl
pkg:rpm/suse/erlang26&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
26.2.1-150300.7.28.1

Ecosystem specific

{
    "binaries":  [
        {
            "erlang26":  "26.2.1-150300.7.28.1",
            "erlang26-epmd":  "26.2.1-150300.7.28.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3579-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP6
erlang26

Package

Name
erlang26
Purl
pkg:rpm/suse/erlang26&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
26.2.1-150300.7.28.1

Ecosystem specific

{
    "binaries":  [
        {
            "erlang26":  "26.2.1-150300.7.28.1",
            "erlang26-epmd":  "26.2.1-150300.7.28.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3579-1.json"