SUSE and openSUSE Address Erlang Path Traversal Vulnerability

SUSE and openSUSE Address Erlang Path Traversal Vulnerability

First seen 3 Sep 2026, 17:39 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

A moderate path traversal vulnerability (CVE-2026-32147) has been identified in Erlang affecting SUSE and openSUSE systems. This vulnerability allows improper limitation of a pathname to a restricted directory in SFTP chroot, potentially enabling unauthorized access to sensitive files. The affected systems include SUSE Linux Enterprise Server 15 SP7 and openSUSE Leap 15.3. Users are advised to apply the provided patches immediately to mitigate risks. The vulnerability was published on April 21, 2026, and has a CVSS score of 4.0. Patch instructions are available through standard SUSE installation methods. The vulnerability is not currently reported to be actively exploited. Administrators should prioritize updating their systems to maintain security.

Key Points: • CVE-2026-32147 affects SUSE and openSUSE systems with a CVSS score of 4.0. • The vulnerability allows path traversal in SFTP chroot, risking unauthorized file access. • Patches are available and should be applied immediately to affected systems.

Timeline

2026-04-21
CVE-2026-32147 published
A path traversal vulnerability in Erlang was disclosed, affecting multiple SUSE and openSUSE systems.
Linuxsecurity
2026-09-03
Patch released for CVE-2026-32147
SUSE released patches for the vulnerability, urging users to update their systems immediately.
Linuxsecurity