gpp_maybe
Security update for erlang26
SUSE-SLE-Module-Server-Applications-15-SP7-2026-2010
This update for erlang26 fixes the following issues Security issues: - CVE-2026-21620: remote arbitrary read/write via TFTP relative path traversal (bsc#1258663). - CVE-2026-23941: HTTP Request Smuggling in Erlang OTP (bsc#1259687). - CVE-2026-23942: path traversal vulnerability in Erlang OTP (bsc#1259681). - CVE-2026-23943: denial of service due to improper handling of highly compressed data in Erlang OTP ssh (bsc#1259682). - CVE-2026-28808: incorrect authorization can lead to unauthenticated access to protected CGI scripts (bsc#1261728). - CVE-2026-32147: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in SFTP chroot (bsc#1262503). Non security issue: - Fixes for FIPS mode (jsc#PED-15166.
-
Release DateMay 19 2026
-
ReferencesBugzilla: 1258663, 1259681, 1259682, 1259687, 1261728, 1262503
CVEs: CVE-2026-21620, CVE-2026-23941, CVE-2026-23942, CVE-2026-23943, CVE-2026-28808, CVE-2026-32147 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Server Applications Module 15.7 aarch64
-
Packageserlang26
General-purpose programming language and runtime environmenterlang26-epmd26.2.1-150300.7.25.1 lock rpm lock src
Erlang Port Mapper daemon26.2.1-150300.7.25.1 lock rpm
Server Applications Module 15.7 s390x
-
Packageserlang26
General-purpose programming language and runtime environmenterlang26-epmd26.2.1-150300.7.25.1 lock rpm lock src
Erlang Port Mapper daemon26.2.1-150300.7.25.1 lock rpm
Server Applications Module 15.7 ppc64le
-
Packageserlang26
General-purpose programming language and runtime environmenterlang26-epmd26.2.1-150300.7.25.1 lock rpm lock src
Erlang Port Mapper daemon26.2.1-150300.7.25.1 lock rpm
Server Applications Module 15.7 x86_64
-
Packageserlang26
General-purpose programming language and runtime environmenterlang26-epmd26.2.1-150300.7.25.1 lock rpm lock src
Erlang Port Mapper daemon26.2.1-150300.7.25.1 lock rpm