RHSA-2026:63160HighCVSS 8.2

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
September 3, 2026
Last Modified
October 2, 2026

🔗 CVE IDs covered (11)

📋 Description

CVE-2026-42789 — erlang: Erlang OTP public_key: Certificate chain forgery via improper trust chain validation CVE-2026-42790 — erlang: Erlang OTP public_key: Certificate validation bypass allows hostname spoofing CVE-2026-42791 — erlang: Erlang OTP: Authentication bypass due to improper OCSP certificate validation CVE-2026-48855 — erlang: Erlang OTP ssh: Information disclosure via symlink resolution in SFTP CVE-2026-48858 — erlang: erlang-inets: erlang-ftp: Erlang/OTP ftp: Server-Side Request Forgery (SSRF) via unvalidated PASV response IP address CVE-2026-48860 — erlang: Erlang/OTP: Authentication bypass allows arbitrary code execution via improper IP address validation CVE-2026-49759 — erlang: Erlang OTP: Denial of Service via crafted SCTP ERROR chunk CVE-2026-54886 — erlang: Erlang OTP ssh: Denial of Service via infinite loop in SFTP channel CVE-2026-54891 — erlang: Erlang SSL: Unauthenticated data injection during TLS handshake CVE-2026-55952 — erlang: Erlang/OTP: Denial of Service in TLS 1.3 session ticket handling CVE-2026-75538 — erlang: Erlang/OTP: Remote denial of service via signed length overflow in TCP driver

🎯 Affected products80

  • Red Hat Hardened Images
  • erlang27-0:27.3.4.17-1.hum1@aarch64 as a component of Red Hat Hardened Images
  • erlang27-0:27.3.4.17-1.hum1@src as a component of Red Hat Hardened Images
  • erlang27-0:27.3.4.17-1.hum1@x86_64 as a component of Red Hat Hardened Images
  • erlang27-asn1-0:27.3.4.17-1.hum1@aarch64 as a component of Red Hat Hardened Images
  • erlang27-asn1-0:27.3.4.17-1.hum1@x86_64 as a component of Red Hat Hardened Images
  • erlang27-common_test-0:27.3.4.17-1.hum1@aarch64 as a component of Red Hat Hardened Images
  • erlang27-common_test-0:27.3.4.17-1.hum1@x86_64 as a component of Red Hat Hardened Images
  • erlang27-compiler-0:27.3.4.17-1.hum1@aarch64 as a component of Red Hat Hardened Images
  • erlang27-compiler-0:27.3.4.17-1.hum1@x86_64 as a component of Red Hat Hardened Images
  • erlang27-crypto-0:27.3.4.17-1.hum1@aarch64 as a component of Red Hat Hardened Images
  • erlang27-crypto-0:27.3.4.17-1.hum1@x86_64 as a component of Red Hat Hardened Images
  • erlang27-debugger-0:27.3.4.17-1.hum1@aarch64 as a component of Red Hat Hardened Images
  • erlang27-debugger-0:27.3.4.17-1.hum1@x86_64 as a component of Red Hat Hardened Images
  • erlang27-dialyzer-0:27.3.4.17-1.hum1@aarch64 as a component of Red Hat Hardened Images
  • erlang27-dialyzer-0:27.3.4.17-1.hum1@x86_64 as a component of Red Hat Hardened Images
  • erlang27-diameter-0:27.3.4.17-1.hum1@aarch64 as a component of Red Hat Hardened Images
  • erlang27-diameter-0:27.3.4.17-1.hum1@x86_64 as a component of Red Hat Hardened Images
  • erlang27-edoc-0:27.3.4.17-1.hum1@aarch64 as a component of Red Hat Hardened Images
  • erlang27-edoc-0:27.3.4.17-1.hum1@x86_64 as a component of Red Hat Hardened Images
  • erlang27-eldap-0:27.3.4.17-1.hum1@aarch64 as a component of Red Hat Hardened Images
  • erlang27-eldap-0:27.3.4.17-1.hum1@x86_64 as a component of Red Hat Hardened Images
  • erlang27-erl_interface-0:27.3.4.17-1.hum1@aarch64 as a component of Red Hat Hardened Images
  • erlang27-erl_interface-0:27.3.4.17-1.hum1@x86_64 as a component of Red Hat Hardened Images
  • erlang27-erts-0:27.3.4.17-1.hum1@aarch64 as a component of Red Hat Hardened Images
  • erlang27-erts-0:27.3.4.17-1.hum1@x86_64 as a component of Red Hat Hardened Images
  • erlang27-et-0:27.3.4.17-1.hum1@aarch64 as a component of Red Hat Hardened Images
  • erlang27-et-0:27.3.4.17-1.hum1@x86_64 as a component of Red Hat Hardened Images
  • erlang27-eunit-0:27.3.4.17-1.hum1@aarch64 as a component of Red Hat Hardened Images
  • erlang27-eunit-0:27.3.4.17-1.hum1@x86_64 as a component of Red Hat Hardened Images
  • +50 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: Ensure all TLS certificates used in the deployment include Subject Alternative Name (SAN) extensions with the appropriate DNS entries. Certificates relying solely on the CommonName (CN) field for hostname identification are susceptible to this bypass. For Erlang applications, the verify_fun option in the ssl module can be configured to reject peer certificates missing the subjectAltName extension. Workaround: For TLS clients using the Erlang ssl application, disable OCSP stapling by setting {stapling, no_staple} in the client options, or switch to CRL-based revocation checking with {crl_check, true}. For applications calling public_key:pkix_ocsp_validate/5 directly, validate the responder certificate's validity period in application code before calling the function. Workaround: To mitigate this vulnerability, restrict network access for systems using the Erlang/OTP FTP client to only trusted FTP servers. Implement firewall rules to limit outbound connections from Erlang/OTP applications to known, legitimate FTP server IP addresses and ports. If the Erlang/OTP `ftp` application is not required, consider disabling or removing it to eliminate the attack surface. Workaround: To mitigate this issue, restrict network access to the Erlang distribution port (default 4369) to only trusted hosts and networks using firewall rules. If Erlang distribution over TLS is not essential for your deployment, consider disabling it. Example using `firewalld` to limit access to port 4369: ```bash sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" port port="4369" protocol="tcp" source address="<TRUSTED_IP_OR_NETWORK>" accept' sudo firewall-cmd --reload ``` Replace `<TRUSTED_IP_OR_NETWORK>` with the specific IP address or network range that should be allowed to access the Erlang distribution. This may impact the functionality of services relying on Erlang distribution from untrusted networks. Workaround: Set the max_channels daemon option to a finite value instead of the default 'infinity' to limit the number of channels an authenticated user can open per connection, reducing the amplification potential of this vulnerability. Workaround: Restarting the ssl application restores TLS 1.3 functionality after a crash. TLS 1.2 connections are not affected. Disabling TLS 1.3 session tickets (stateful and stateless) eliminates the attack surface.

🔗 References (16)