Skip to content
SUSE erlang26 Important System Patch for 22 Issues Advisory 2026-3579

SUSE erlang26 Important System Patch for 22 Issues Advisory 2026-3579

Linuxsecurity •LinuxSecurity Advisories • August 12, 2026

Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×

## This update for erlang26 fixes the following issues: * CVE-2026-28810: predictable DNS transaction IDs can cause DNS cache poisoning (bsc#1261726). * CVE-2026-42789: `public_key` application accepts non-CA certificates as intermediate issuers and this enables chain forgery (bsc#1266449). * CVE-2026-42790: Name constraints and `Subject CommonName` fallback in TLS hostname verification allows for certificate forgery by MITM attacker (bsc#1266466). * CVE-2026-42792: permanent `epmd` DoS via connection slot exhaustion due to improper handling of exceptional conditions (bsc#1272908). * CVE-2026-47078: relative path traversal in `zip:unzip/zip:extract` via `check_dir_level` depth-counter bypass (bsc#1272909). * CVE-2026-48855: SFTP `READLINK` response leaks absolute backend filesystem

## This update for erlang26 fixes the following issues: * CVE-2026-28810: predictable DNS transaction IDs can cause DNS cache poisoning (bsc#1261726). * CVE-2026-42789: `public_key` application accepts non-CA certificates as intermediate issuers and this enables chain forgery (bsc#1266449). * CVE-2026-42790: Name constraints and `Subject CommonName` fallback in TLS hostname verification allows for certificate forgery by MITM attacker (bsc#1266466). * CVE-2026-42792: permanent `epmd` DoS via connection slot exhaustion due to improper handling of exceptional conditions (bsc#1272908). * CVE-2026-47078: relative path traversal in `zip:unzip/zip:extract` via `check_dir_level` depth-counter bypass (bsc#1272909). * CVE-2026-48855: SFTP `READLINK` response leaks absolute backend filesystem

* CVE-2026-28810 ( SUSE ): 8.2

CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N

Announcement ID: SUSE-SU-2026:3579-1 Release Date: 2026-08-11T14:05:55Z Rating: important

Get the latest Linux and open source security news straight to your inbox.