SB20260907121 - Fedora 44 update for erlang



SB20260907121 - Fedora 44 update for erlang

Published: September 7, 2026 Updated: September 30, 2026

Security Bulletin ID SB20260907121
CSH Severity
High
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 33% Medium 67%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Uncontrolled Recursion (CVE-ID: CVE-2026-58227)

CWE-ID: CWE-674 - Uncontrolled Recursion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled recursion in certificate chain path building when processing peer certificate messages during a partial TLS or DTLS handshake. A remote attacker can send a certificate chain containing two mutually cross-signed certificates in unordered form to cause a denial of service.

No authentication or completed handshake is required, and both client and server sides are affected.


2) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-59251)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in certificate path validation when processing a crafted certificate chain during the TLS handshake. A remote attacker can send a specially crafted certificate chain to cause a denial of service.

Any application using TLS certificate path validation through the ssl functionality or direct calls to public_key:pkix_path_validation/3 is affected.


3) Algorithm Downgrade (CVE-ID: CVE-2026-55953)

CWE-ID: CWE-757 - Selection of Less-Secure Algorithm During Negotiat

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read and modify data transmitted over the connection.

The vulnerability exists due to selection of a less-secure algorithm during negotiation in the OTP TLS/DTLS client cipher suite validation logic when processing a ServerHello message. A remote attacker can select an anonymous cipher suite that was not offered by the client to read and modify data transmitted over the connection.

This affects TLS versions up to 1.2 and all DTLS versions, while TLS-1.3 connections are not affected. The issue can bypass the client's verify_peer setting because anonymous cipher suites do not require a server certificate.


Remediation

Install update from vendor's website.