Back Linuxsecurity SUSE erlang26 Important System Patch for 22 Issues Advisory 2026-3579
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
## This update for erlang26 fixes the following issues: * CVE-2026-28810: predictable DNS transaction IDs can cause DNS cache poisoning (bsc#1261726). * CVE-2026-42789: `public_key` application accepts non-CA certificates as intermediate issuers and this enables chain forgery (bsc#1266449). * CVE-2026-42790: Name constraints and `Subject CommonName` fallback in TLS hostname verification allows for certificate forgery by MITM attacker (bsc#1266466). * CVE-2026-42792: permanent `epmd` DoS via connection slot exhaustion due to improper handling of exceptional conditions (bsc#1272908). * CVE-2026-47078: relative path traversal in `zip:unzip/zip:extract` via `check_dir_level` depth-counter bypass (bsc#1272909). * CVE-2026-48855: SFTP `READLINK` response leaks absolute backend filesystem
## This update for erlang26 fixes the following issues: * CVE-2026-28810: predictable DNS transaction IDs can cause DNS cache poisoning (bsc#1261726). * CVE-2026-42789: `public_key` application accepts non-CA certificates as intermediate issuers and this enables chain forgery (bsc#1266449). * CVE-2026-42790: Name constraints and `Subject CommonName` fallback in TLS hostname verification allows for certificate forgery by MITM attacker (bsc#1266466). * CVE-2026-42792: permanent `epmd` DoS via connection slot exhaustion due to improper handling of exceptional conditions (bsc#1272908). * CVE-2026-47078: relative path traversal in `zip:unzip/zip:extract` via `check_dir_level` depth-counter bypass (bsc#1272909). * CVE-2026-48855: SFTP `READLINK` response leaks absolute backend filesystem
* CVE-2026-28810 ( SUSE ): 8.2
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Announcement ID: SUSE-SU-2026:3579-1 Release Date: 2026-08-11T14:05:55Z Rating: important
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
