Linuxsecurity
Critical Denial of Service Vulnerabilities in Fedora Erlang Packages Addressed
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Multiple critical vulnerabilities have been identified in Fedora's Erlang packages, specifically affecting erlang-gun and erlang-cowboy. CVE-2026-43972 involves a cross-origin cookie injection leading to session fixation and account takeover, while CVE-2026-43974 and CVE-2026-43973 address Denial of Service (DoS) vulnerabilities. The vulnerabilities were published on June 8, 2026, and impact Fedora 43 and 44 users. Users are urged to update their systems immediately to mitigate these risks. The updates can be installed using the 'dnf' update program. The vulnerabilities were reported by Peter Lemenkov, a Fedora maintainer. The affected versions include erlang-gun 2.4.0 and 2.4.1, and erlang-cowboy 2.16.0 and 2.16.1. Current advisories emphasize the urgency of applying the patches.
Key Points: • Critical vulnerabilities in Fedora's Erlang packages affect multiple versions. • CVE-2026-43972 allows for session fixation and account takeover. • Immediate updates are necessary to mitigate Denial of Service risks.