Advisories ยป MGASA-2026-0457

Updated erlang package fixes security vulnerabilities

Publication date: 27 Sep 2026
Modification date: 27 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-54886 , CVE-2026-54891 , CVE-2026-54892 , CVE-2026-54893 , CVE-2026-55952 , CVE-2026-55953

Description

SSH SFTP server denial of service via extended channel data infinite
loop. (CVE-2026-54886)
Plaintext APPLICATION_DATA injected during TLS handshake delivered to
client application post-handshake in ssl. (CVE-2026-54891)
Plug: quadratic-time decoding of nested query/body parameters enables
denial of service. (CVE-2026-54892)
Email-derived URL path injection in the Swoosh Microsoft Graph adapter.
(CVE-2026-54893)
                

References

SRPMS

10/core