Critical openSUSE Erlang 26 Patch Addresses 22 Vulnerabilities

Critical openSUSE Erlang 26 Patch Addresses 22 Vulnerabilities

First seen 12 Aug 2026, 04:25 UTC www.suse.comLinuxsecurity 95% similarity 72.0

Article Content

Browse articles
ThreatCluster

On August 12, 2026, an important patch was released for the openSUSE Erlang 26 system, addressing 22 vulnerabilities. Key issues include CVE-2026-28810, which allows DNS cache poisoning, and CVE-2026-42789, enabling certificate chain forgery. Other vulnerabilities include a permanent denial of service (CVE-2026-42792) and a relative path traversal flaw (CVE-2026-47078). The vulnerabilities affect various components of the Erlang system, including the `public_key` application and SFTP functionalities. Users are urged to apply the patch immediately to mitigate potential exploitation. The vulnerabilities were published between April and July 2026, with the patch released on the same day as the advisory. The update is critical for maintaining system integrity and security.

Key Points: • The patch addresses 22 vulnerabilities in the openSUSE Erlang 26 system. • Critical CVEs include CVE-2026-28810 (DNS cache poisoning) and CVE-2026-42789 (certificate forgery). • Users are advised to apply the patch immediately to prevent potential exploitation.

ThreatCluster AI How this analysis works

Timeline

2026-04-07
CVE-2026-28810 published
Predictable DNS transaction IDs can lead to DNS cache poisoning, affecting system integrity.
Linuxsecurity
2026-05-27
CVE-2026-42789 published
The `public_key` application allows non-CA certificates as intermediate issuers, enabling chain forgery.
Linuxsecurity
2026-05-27
CVE-2026-42790 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-10
CVE-2026-48855 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-10
CVE-2026-48856 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-07-27
CVE-2026-42792 published
Improper handling of exceptional conditions leads to a permanent denial of service via `epmd` connection slot exhaustion.
Linuxsecurity
2026-07-27
CVE-2026-47078 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-12
Patch released for Erlang 26 vulnerabilities
An important patch was released addressing 22 vulnerabilities in the openSUSE Erlang 26 system, with immediate application recommended.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story