Updated erlang package fixes security vulnerabilities
Publication date: 27 Sep 2026Modification date: 27 Sep 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-54886 , CVE-2026-54891 , CVE-2026-54892 , CVE-2026-54893 , CVE-2026-55952 , CVE-2026-55953
Description
SSH SFTP server denial of service via extended channel data infinite
loop. (CVE-2026-54886)
Plaintext APPLICATION_DATA injected during TLS handshake delivered to
client application post-handshake in ssl. (CVE-2026-54891)
Plug: quadratic-time decoding of nested query/body parameters enables
denial of service. (CVE-2026-54892)
Email-derived URL path injection in the Swoosh Microsoft Graph adapter.
(CVE-2026-54893)
References
- https://bugs.mageia.org/show_bug.cgi?id=35971
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z643GQLCV3X4YNAD2P52IFBKQQU7E7A5/
- https://github.com/erlang/otp/security/advisories/GHSA-7wp4-pc27-2vj9
- https://cna.erlef.org/cves/CVE-2026-54886.html
- https://osv.dev/vulnerability/EEF-CVE-2026-54886
- https://github.com/erlang/otp/security/advisories/GHSA-gf6r-99xw-6qg6
- https://cna.erlef.org/cves/CVE-2026-54891.html
- https://osv.dev/vulnerability/EEF-CVE-2026-54891
- https://osv.dev/vulnerability/EEF-CVE-2026-55952
- https://cna.erlef.org/cves/CVE-2026-55952.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/45JCTFOGPTE2S5BCCCJH6KKGFNKZIDVS/
- https://github.com/erlang/otp/security/advisories/GHSA-c6cw-pr89-w882
- https://cna.erlef.org/cves/CVE-2026-55953.html
- https://osv.dev/vulnerability/EEF-CVE-2026-55953
- https://github.com/erlang/otp/releases/tag/OTP-27.3.4.16
- https://github.com/erlang/otp/releases/tag/OTP-27.3.4.17
- https://www.cve.org/CVERecord?id=CVE-2026-54886
- https://www.cve.org/CVERecord?id=CVE-2026-54891
- https://www.cve.org/CVERecord?id=CVE-2026-54892
- https://www.cve.org/CVERecord?id=CVE-2026-54893
- https://www.cve.org/CVERecord?id=CVE-2026-55952
- https://www.cve.org/CVERecord?id=CVE-2026-55953
SRPMS
10/core
- erlang-27.3.4.17-1.mga10