Security update for erlang26
This update for erlang26 fixes the following issues: - CVE-2026-28810: predictable DNS transaction IDs can cause DNS cache poisoning (bsc#1261726). - CVE-2026-42789: `public_key` application accepts non-CA certificates as intermediate issuers and this enables chain forgery (bsc#1266449). - CVE-2026-42790: Name constraints and `Subject CommonName` fallback in TLS hostname verification allows for certificate forgery by MITM attacker (bsc#1266466). - CVE-2026-42792: permanent `epmd` DoS via connection slot exhaustion due to improper handling of exceptional conditions (bsc#1272908). - CVE-2026-47078: relative path traversal in `zip:unzip/zip:extract` via `check_dir_level` depth-counter bypass (bsc#1272909). - CVE-2026-48855: SFTP `READLINK` response leaks absolute backend filesystem path when root is configured (bsc#1268139). - CVE-2026-48856: `httpc` leaks `Authorization` headers to cross-origin redirect targets (bsc#1268141). - CVE-2026-48858: server-side request forgery allows FTP bounce attacks and SSRF via an unvalidated `PASV` response IP address (bsc#1268142). - CVE-2026-48860: `ssl` (`inet_tls_dist` module) allows unauthenticated bypass of the distribution-over-TLS LAN allowlist (bsc#1268146). - CVE-2026-49759: unbounded stack buffer overflow in SCTP error cause parsing in `inet_drv` (bsc#1268163). - CVE-2026-49760: stack buffer overflow in `ei_s_print_term` at very large integer (bsc#1268164). - CVE-2026-53422: SFTP `REALPATH` path-existence oracle allows filesystem enumeration outside configured root (bsc#1270245). - CVE-2026-54886: SSH SFTP server denial of service via extended channel data infinite loop (bsc#1270246). - CVE-2026-54887: use of default cryptographic key allows predictable DTLS cookie computation during the startup window (bsc#1270247). - CVE-2026-54891: plaintext injection towards (D)TLS client during handshake (bsc#1270250). - CVE-2026-55737: heap pointer corruption via signed/unsigned mismatch in `LARGE_TUPLE_EXTP` decoding in `erts` external term format decoder (bsc#1272910). - CVE-2026-55950: time-of-check time-of-use race condition allows an unauthenticated remote attacker to crash all active DTLS sessions on a listener (bsc#1270253). - CVE-2026-55952: missing validation allows for DoS of the TLS-1.3 server when clients send a malformed `ClientHello` with mismatched PSK identity and binder list lengths (bsc#1270258). - CVE-2026-55953: TLS 1.2 and DTLS clients accept unoffered anonymous cipher suites and allow for server authentication bypass (bsc#1272911). - CVE-2026-58227: TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain (bsc#1272913). - CVE-2026-59250: `megaco` flex scanner buffer overflow via oversized property parm name (bsc#1272914). - CVE-2026-59251: denial of service via exponential certificate policy tree growth in path validation (bsc#1272915).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for erlang26 fixes the following issues: - CVE-2026-28810: predictable DNS transaction IDs can cause DNS cache poisoning (bsc#1261726). - CVE-2026-42789: `public_key` application accepts non-CA certificates as intermediate issuers and this enables chain forgery (bsc#1266449). - CVE-2026-42790: Name constraints and `Subject CommonName` fallback in TLS hostname verification allows for certificate forgery by MITM attacker (bsc#1266466). - CVE-2026-42792: permanent `epmd` DoS via connection slot exhaustion due to improper handling of exceptional conditions (bsc#1272908). - CVE-2026-47078: relative path traversal in `zip:unzip/zip:extract` via `check_dir_level` depth-counter bypass (bsc#1272909). - CVE-2026-48855: SFTP `READLINK` response leaks absolute backend filesystem path when root is configured (bsc#1268139). - CVE-2026-48856: `httpc` leaks `Authorization` headers to cross-origin redirect targets (bsc#1268141). - CVE-2026-48858: server-side request forgery allows FTP bounce attacks and SSRF via an unvalidated `PASV` response IP address (bsc#1268142). - CVE-2026-48860: `ssl` (`inet_tls_dist` module) allows unauthenticated bypass of the distribution-over-TLS LAN allowlist (bsc#1268146). - CVE-2026-49759: unbounded stack buffer overflow in SCTP error cause parsing in `inet_drv` (bsc#1268163). - CVE-2026-49760: stack buffer overflow in `ei_s_print_term` at very large integer (bsc#1268164). - CVE-2026-53422: SFTP `REALPATH` path-existence oracle allows filesystem enumeration outside configured root (bsc#1270245). - CVE-2026-54886: SSH SFTP server denial of service via extended channel data infinite loop (bsc#1270246). - CVE-2026-54887: use of default cryptographic key allows predictable DTLS cookie computation during the startup window (bsc#1270247). - CVE-2026-54891: plaintext injection towards (D)TLS client during handshake (bsc#1270250). - CVE-2026-55737: heap pointer corruption via signed/unsigned mismatch in `LARGE_TUPLE_EXTP` decoding in `erts` external term format decoder (bsc#1272910). - CVE-2026-55950: time-of-check time-of-use race condition allows an unauthenticated remote attacker to crash all active DTLS sessions on a listener (bsc#1270253). - CVE-2026-55952: missing validation allows for DoS of the TLS-1.3 server when clients send a malformed `ClientHello` with mismatched PSK identity and binder list lengths (bsc#1270258). - CVE-2026-55953: TLS 1.2 and DTLS clients accept unoffered anonymous cipher suites and allow for server authentication bypass (bsc#1272911). - CVE-2026-58227: TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain (bsc#1272913). - CVE-2026-59250: `megaco` flex scanner buffer overflow via oversized property parm name (bsc#1272914). - CVE-2026-59251: denial of service via exponential certificate policy tree growth in path validation (bsc#1272915).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1261726
- https://bugzilla.suse.com/1266449
- https://bugzilla.suse.com/1266466
- https://bugzilla.suse.com/1268139
- https://bugzilla.suse.com/1268141
- https://bugzilla.suse.com/1268142
- https://bugzilla.suse.com/1268146
- https://bugzilla.suse.com/1268163
- https://bugzilla.suse.com/1268164
- https://bugzilla.suse.com/1270245
- https://bugzilla.suse.com/1270246
- https://bugzilla.suse.com/1270247
- https://bugzilla.suse.com/1270250
- https://bugzilla.suse.com/1270253
- https://bugzilla.suse.com/1270258
- https://bugzilla.suse.com/1272908
- https://bugzilla.suse.com/1272909
- https://bugzilla.suse.com/1272910
- https://bugzilla.suse.com/1272911
- https://bugzilla.suse.com/1272913
- https://bugzilla.suse.com/1272914
- https://bugzilla.suse.com/1272915
- https://www.suse.com/security/cve/CVE-2026-28810
- https://www.suse.com/security/cve/CVE-2026-42789
- https://www.suse.com/security/cve/CVE-2026-42790
- https://www.suse.com/security/cve/CVE-2026-42792
- https://www.suse.com/security/cve/CVE-2026-47078
- https://www.suse.com/security/cve/CVE-2026-48855
- https://www.suse.com/security/cve/CVE-2026-48856
- https://www.suse.com/security/cve/CVE-2026-48858
- https://www.suse.com/security/cve/CVE-2026-48860
- https://www.suse.com/security/cve/CVE-2026-49759
- https://www.suse.com/security/cve/CVE-2026-49760
- https://www.suse.com/security/cve/CVE-2026-53422
- https://www.suse.com/security/cve/CVE-2026-54886
- https://www.suse.com/security/cve/CVE-2026-54887
- https://www.suse.com/security/cve/CVE-2026-54891
- https://www.suse.com/security/cve/CVE-2026-55737
- https://www.suse.com/security/cve/CVE-2026-55950
- https://www.suse.com/security/cve/CVE-2026-55952
- https://www.suse.com/security/cve/CVE-2026-55953
- https://www.suse.com/security/cve/CVE-2026-58227
- https://www.suse.com/security/cve/CVE-2026-59250
- https://www.suse.com/security/cve/CVE-2026-59251
- https://www.suse.com/support/update/announcement/2026/suse-su-20263579-1/