Critical Denial of Service and Auth Bypass Vulnerabilities in Fedora Erlang

Critical Denial of Service and Auth Bypass Vulnerabilities in Fedora Erlang

First seen 19 Jul 2026, 19:46 UTC Linuxsecurityfedoraproject.org 95% similarity 70.5

Article Content

Browse articles
ThreatCluster

Fedora has issued backport fixes for multiple vulnerabilities in Erlang affecting versions 26.x and 27.x. Key vulnerabilities include CVE-2026-48858 (SSRF), CVE-2026-49759 (SCTP DoS), CVE-2026-48860 (auth bypass), CVE-2026-54886 (SFTP DoS), CVE-2026-54891 (TLS handshake injection), and CVE-2026-55952 (TLS 1.3 session ticket DoS). These vulnerabilities could allow attackers to execute arbitrary code or cause service disruptions. The vulnerabilities were published between June 10 and July 2, 2026, with fixes backported on July 10, 2026. Users are advised to update their systems using the provided commands to mitigate these risks. The affected systems include Fedora 43 and 44, impacting a wide range of users reliant on Erlang for applications.

Key Points: • Multiple critical vulnerabilities in Fedora Erlang require immediate attention. • CVE-2026-48860 allows for authentication bypass, posing a significant risk. • Users should apply the latest updates to mitigate potential exploitation.

ThreatCluster AI

Timeline

2026-06-10
CVE-2026-48858 published
A Server-Side Request Forgery vulnerability in Erlang/OTP was disclosed, allowing unvalidated PASV response IP addresses.
Linuxsecurity
2026-06-10
CVE-2026-49759 published
A Denial of Service vulnerability via crafted SCTP ERROR chunk was disclosed in Erlang OTP.
Linuxsecurity
2026-06-10
CVE-2026-48860 published
An authentication bypass vulnerability allowing arbitrary code execution was disclosed in Erlang/OTP.
Linuxsecurity
2026-07-02
CVE-2026-54891 published
A vulnerability allowing unauthenticated data injection during the TLS handshake was disclosed in Erlang SSL.
Linuxsecurity
2026-07-02
CVE-2026-55952 published
A Denial of Service vulnerability related to TLS 1.3 session tickets was disclosed in Erlang.
Linuxsecurity
2026-07-02
CVE-2026-54886 published
A Denial of Service vulnerability due to an infinite loop in the SFTP channel was disclosed in Erlang OTP.
Linuxsecurity
2026-07-10
Backport fixes released
Fedora backported fixes for multiple CVEs affecting Erlang, including critical vulnerabilities.
Linuxsecurity

Community

Browse all →