gpp_maybe Security update for erlang
SUSE-SLE-Module-Server-Applications-15-SP7-2026-3645


This update for erlang fixes the following issues: - CVE-2026-28810: predictable DNS transaction IDs can cause DNS cache poisoning (bsc#1261726). - CVE-2026-42789: `public_key` application accepts non-CA certificates as intermediate issuers and this enables chain forgery (bsc#1266449). - CVE-2026-42790: Name constraints and `Subject CommonName` fallback in TLS hostname verification allows for certificate forgery by MITM attacker (bsc#1266466). - CVE-2026-42792: permanent `epmd` DoS via connection slot exhaustion due to improper handling of exceptional conditions (bsc#1272908). - CVE-2026-47078: relative path traversal in `zip:unzip/zip:extract` via `check_dir_level` depth-counter bypass (bsc#1272909). - CVE-2026-48855: SFTP `READLINK` response leaks absolute backend filesystem path when root is configured (bsc#1268139). - CVE-2026-48856: `httpc` leaks `Authorization` headers to cross-origin redirect targets (bsc#1268141). - CVE-2026-48858: server-side request forgery allows FTP bounce attacks and SSRF via an unvalidated `PASV` response IP address (bsc#1268142). - CVE-2026-49759: unbounded stack buffer overflow in SCTP error cause parsing in `inet_drv` (bsc#1268163). - CVE-2026-49760: stack buffer overflow in `ei_s_print_term` at very large integer (bsc#1268164). - CVE-2026-53422: SFTP `REALPATH` path-existence oracle allows filesystem enumeration outside configured root (bsc#1270245). - CVE-2026-54886: SSH SFTP server denial of service via extended channel data infinite loop (bsc#1270246). - CVE-2026-54887: use of default cryptographic key allows predictable DTLS cookie computation during the startup window (bsc#1270247). - CVE-2026-54891: plaintext injection towards (D)TLS client during handshake (bsc#1270250). - CVE-2026-55737: heap pointer corruption via signed/unsigned mismatch in `LARGE_TUPLE_EXTP` decoding in `erts` external term format decoder (bsc#1272910). - CVE-2026-55952: missing validation allows for DoS of the TLS-1.3 server when clients send a malformed `ClientHello` with mismatched PSK identity and binder list lengths (bsc#1270258). - CVE-2026-55953: TLS 1.2 and DTLS clients accept unoffered anonymous cipher suites and allow for server authentication bypass (bsc#1272911). - CVE-2026-58227: TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain (bsc#1272913). - CVE-2026-59250: `megaco` flex scanner buffer overflow via oversized property parm name (bsc#1272914).


cloud_download Downloads

Server Applications Module 15.7 ppc64le
  • Packages
    erlang
    General-purpose programming language and runtime environment
    23.3.4.19-150300.3.39.1 lock rpm lock src
    erlang-epmd
    Erlang Port Mapper daemon
    23.3.4.19-150300.3.39.1 lock rpm
Server Applications Module 15.7 aarch64
  • Packages
    erlang
    General-purpose programming language and runtime environment
    23.3.4.19-150300.3.39.1 lock rpm lock src
    erlang-epmd
    Erlang Port Mapper daemon
    23.3.4.19-150300.3.39.1 lock rpm
Server Applications Module 15.7 s390x
  • Packages
    erlang
    General-purpose programming language and runtime environment
    23.3.4.19-150300.3.39.1 lock rpm lock src
    erlang-epmd
    Erlang Port Mapper daemon
    23.3.4.19-150300.3.39.1 lock rpm
Server Applications Module 15.7 x86_64
  • Packages
    erlang
    General-purpose programming language and runtime environment
    23.3.4.19-150300.3.39.1 lock rpm lock src
    erlang-epmd
    Erlang Port Mapper daemon
    23.3.4.19-150300.3.39.1 lock rpm