Updated erlang packages fix a security vulnerability
Publication date: 19 Jul 2026Modification date: 19 Jul 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-48855
Description
The updated packages fix a security vulnerability:
SFTP READLINK response leaks absolute backend filesystem path when root
is configured. (CVE-2026-48855)
References
- https://bugs.mageia.org/show_bug.cgi?id=35839
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/O2CL6CSAYWT3KK6GLRNIWD7YDNMWHJ4N/
- https://github.com/erlang/otp/security/advisories/GHSA-pv7g-pjrq-x2fh
- https://cna.erlef.org/cves/CVE-2026-48855.html
- https://osv.dev/vulnerability/EEF-CVE-2026-48855
- https://www.cve.org/CVERecord?id=CVE-2026-48855
SRPMS
10/core
- erlang-27.3.4.13-1.mga10