Security update for erlang
| Announcement ID: | SUSE-SU-2026:21374-1 |
|---|---|
| Release Date: | 2026-04-22T10:52:20Z |
| Rating: | important |
| References: | |
| Cross-References: | |
| CVSS scores: |
|
| Affected Products: |
|
An update that solves seven vulnerabilities and has one fix can now be installed.
Description:
This update for erlang fixes the following issues:
Security issues fixed:
- CVE-2026-21620: improper isolation and compartmentalization can lead to TFTP relative path traversal and remote arbitrary reads/writes (bsc#1258663).
- CVE-2026-23941: improper handling of duplicate Content-Length headers in Erlang OTP can lead to HTTP request smuggling (bsc#1259687).
- CVE-2026-23942: improper limitation of a pathname to a restricted directory in the SFTP server can lead to path traversal (bsc#1259681).
- CVE-2026-23943: improper handling of highly compressed data in Erlang OTP ssh can lead to denial of service (bsc#1259682).
- CVE-2026-28808: incorrect authorization can lead to unauthenticated access to protected CGI scripts (bsc#1261728).
- CVE-2026-28810: predictable DNS transaction IDs can lead to DNS cache poisoning (bsc#1261726).
- CVE-2026-32144: missing signature verification can lead to OCSP authorization bypass and information disclosure (bsc#1261734).
Other updates and bugfixes:
- jinterface: allow to build determenistic OtpErlang.jar (bsc#1262288).
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Enterprise Server for SAP applications 16.0
zypper in -t patch SUSE-SLES-16.0-619=1 -
SUSE Linux Enterprise Server 16.0
zypper in -t patch SUSE-SLES-16.0-619=1
Package List:
-
SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64)
- erlang-epmd-27.1.3-160000.4.1
- erlang-debuginfo-27.1.3-160000.4.1
- erlang-debugsource-27.1.3-160000.4.1
- erlang-27.1.3-160000.4.1
- erlang-epmd-debuginfo-27.1.3-160000.4.1
-
SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64)
- erlang-epmd-27.1.3-160000.4.1
- erlang-debuginfo-27.1.3-160000.4.1
- erlang-debugsource-27.1.3-160000.4.1
- erlang-27.1.3-160000.4.1
- erlang-epmd-debuginfo-27.1.3-160000.4.1
References:
- https://www.suse.com/security/cve/CVE-2026-21620.html
- https://www.suse.com/security/cve/CVE-2026-23941.html
- https://www.suse.com/security/cve/CVE-2026-23942.html
- https://www.suse.com/security/cve/CVE-2026-23943.html
- https://www.suse.com/security/cve/CVE-2026-28808.html
- https://www.suse.com/security/cve/CVE-2026-28810.html
- https://www.suse.com/security/cve/CVE-2026-32144.html
- https://bugzilla.suse.com/show_bug.cgi?id=1258663
- https://bugzilla.suse.com/show_bug.cgi?id=1259681
- https://bugzilla.suse.com/show_bug.cgi?id=1259682
- https://bugzilla.suse.com/show_bug.cgi?id=1259687
- https://bugzilla.suse.com/show_bug.cgi?id=1261726
- https://bugzilla.suse.com/show_bug.cgi?id=1261728
- https://bugzilla.suse.com/show_bug.cgi?id=1261734
- https://bugzilla.suse.com/show_bug.cgi?id=1262288