RHSA-2026:39809HighCVSS 8.0

Red Hat Security Advisory: Red Hat OpenStack Services on OpenShift 18.0 (erlang) security update

Published
July 15, 2026
Last Modified
September 17, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-42789 — erlang: Erlang OTP public_key: Certificate chain forgery via improper trust chain validation CVE-2026-42790 — erlang: Erlang OTP public_key: Certificate validation bypass allows hostname spoofing

🎯 Affected products31

  • Red Hat OpenStack Services on OpenShift 18.0
  • erlang-0:26.2.5.21-2.el9ost.src as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-asn1-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-asn1-debuginfo-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-compiler-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-crypto-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-crypto-debuginfo-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-debuginfo-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-debugsource-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-eldap-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-erl_interface-debuginfo-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-erts-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-erts-debuginfo-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-gdb-tools-debuginfo-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-inets-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-kernel-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-mnesia-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-odbc-debuginfo-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-os_mon-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-os_mon-debuginfo-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-parsetools-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-public_key-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-runtime_tools-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-runtime_tools-debuginfo-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-sasl-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-snmp-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-ssl-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-stdlib-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-syntax_tools-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • erlang-tools-0:26.2.5.21-2.el9ost.x86_64 as a component of Red Hat OpenStack Services on OpenShift 18.0
  • +1 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Ensure all TLS certificates used in the deployment include Subject Alternative Name (SAN) extensions with the appropriate DNS entries. Certificates relying solely on the CommonName (CN) field for hostname identification are susceptible to this bypass. For Erlang applications, the verify_fun option in the ssl module can be configured to reject peer certificates missing the subjectAltName extension.

🔗 References (5)