Security News

Cybersecurity news aggregator

🔄
HIGH Updates Red Hat Errata

RHSA-2026:39809: Important: Red Hat OpenStack Services on OpenShift 18.0 (erlang) security update

This security update addresses two vulnerabilities in the Erlang/OTP `public_key` module: CVE-2026-42789 (CVSS 4.8 MEDIUM) allows certificate chain forgery via improper trust chain validation, and CVE-2026-42790 (CVSS 8.1 HIGH) enables a certificate validation bypass for hostname spoofing. Affected versions are Erlang/OTP 17.0 to 26.2.5.20, 27.0 to 27.3.4.11, 28.0 to 28.5.0.0, and 29.0 to 29.0.0. The fix requires upgrading to Erlang version 26.2.5.21, 27.3.4.12, 28.5.0.1, or 29.0.1, as provided in this Red Hat OpenStack Services on OpenShift 18.0 advisory.
Read Full Article →

Red Hat Product Errata RHSA-2026:39809 - Security Advisory Issued: 2026-07-15 Updated: 2026-07-15 RHSA-2026:39809 - Security Advisory Overview Updated Packages Synopsis Important: Red Hat OpenStack Services on OpenShift 18.0 (erlang) security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for erlang is now available for Red Hat OpenStack Services on OpenShift 18.0 (Antelope). Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Erlang is a general-purpose programming language and runtime environment. Erlang has built-in support for concurrency, distribution and fault tolerance. Erlang is used in several large telecommunication systems from Ericsson. Security Fix(es): Erlang OTP public_key: Certificate chain forgery via improper trust chain validation (CVE-2026-42789) Erlang OTP public_key: Certificate validation bypass allows hostname spoofing (CVE-2026-42790) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat OpenStack Services on OpenShift 18.0 x86_64 Fixes BZ - 2482093 - CVE-2026-42789 erlang: Erlang OTP public_key: Certificate chain forgery via improper trust chain validation BZ - 2482286 - CVE-2026-42790 erlang: Erlang OTP public_key: Certificate validation bypass allows hostname spoofing CVEs CVE-2026-42789 CVE-2026-42790 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat OpenStack Services on OpenShift 18.0 SRPM erlang-26.2.5.21-2.el9ost.src.rpm SHA-256: 3c1ea06400d57dfa39ac974786056155d40dea51c98a3af9b584d5307b328639 x86_64 erlang-asn1-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: a191bb586146d3bfc13844039fed8dbd4cdbff928a5bf6838834d91cbce943e4 erlang-asn1-debuginfo-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: 12f2133cf7f3ce8c99d711aa34240daff5c14f64c2535f4c52dc73317918514c erlang-compiler-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: 4d6824cda0c19c870995db4ea7044b4f703266b445701b8b1ada99e0e375aac7 erlang-crypto-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: 27a976909ec4aa921b9a6993b744d3e5b1bf8eaebcd998b36c409da4b173bb1f erlang-crypto-debuginfo-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: 5fa94aca7f88a808b5b81665dadd3b2bc246bc125875356bbba58b8521603718 erlang-debuginfo-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: 60bb5f11bce21655751b595310301813fb94dd7e540e3ca54d674a54fb7296b8 erlang-debugsource-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: 1b991f93c6aee977c8c8efaecdb9204a199d0b99cd48c99d4c270471166383c6 erlang-eldap-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: 29da49e419cecc40d18fb390dbb068a73be201ed48a347b286062a61a784a86e erlang-erl_interface-debuginfo-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: a32b219b1f942d5f27052c0150ced82eef6abac6df08abe0fb870196db0a44b7 erlang-erts-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: 7ac78fdf02d38643d85a407a2fc2a0d5f7cbdcec81132d2d6f25618a96a1766a erlang-erts-debuginfo-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: 3fb7ba1a67fb67b4d66fa8aaa05e51c19475de2ac62a1b9f0d1f2393b362c6db erlang-gdb-tools-debuginfo-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: f36a8850fb4e3cf85494b4c661659c2317790ab2dd01c37c3fac3020eac11d2f erlang-inets-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: 3bfc851a0aa8adb20acec99923ebec88b1cda8bb730e847acdb79ca096e2d6ed erlang-kernel-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: b9d73de4ba205784da0975bdfa1c1a1e5651d49bc2958c0982c4a29a7e5d0592 erlang-mnesia-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: 13605dd377a7fd49b64dca3dd59d2b346ee2477617ecb544b4ae490326db55c7 erlang-odbc-debuginfo-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: 69ea64b3dae73a7376c6b173e891b2d4797471d2471f9d9fe8f72b5dc92ac916 erlang-os_mon-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: 0fc54e435bb7ff88631ead601505da8b695babcd8802f81da1d59dad0cfd660d erlang-os_mon-debuginfo-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: ff0d55fb3d79a4a02587698a00bb2e7bfecb5f5f3128ea00766e5f9762434008 erlang-parsetools-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: 6d7d4854cc09ce0ce1b9e354b2bfacac4f67ff81a4db602e4d5a89c686d195a9 erlang-public_key-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: d401ea4fd20d25ac721b21cf9dd0e3eed698518d35bb81c68227e47b3a0f4b06 erlang-runtime_tools-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: 2c4c0002bfea4d12ce300076de368b461cdd6015c57c144173c3abb24df9267c erlang-runtime_tools-debuginfo-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: 1c4dba25308ba8d8bd9ca62620945ae17fe4077017f9d3d11d21a2a6f9c84150 erlang-sasl-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: 54fd00c61f48d484a044a4ddc7a934c4e7491049caa6a55e02f8182fe6f94a19 erlang-snmp-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: c52b6bf937ea681f3b473df04b3d1c71f62be343620c48a60999f513215e48cd erlang-ssl-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: b0d4c130b7e6546080d2fc3521038f5c1fe6f4c43d67de95ac25562a36f66f1e erlang-stdlib-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: d720f53c1f78ab549e1ee3624c49636e28560692e1e66d5e8e44a352de053551 erlang-syntax_tools-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: 1ef436d37e3d242deac862aa02271cca72014beea173b840b821a8ae137ef486 erlang-tools-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: e3f19a97da2d84a6a761de93a9a74f51c136b16c8ff71157a52111961b8c83f3 erlang-xmerl-26.2.5.21-2.el9ost.x86_64.rpm SHA-256: 11e52f723108878ebf6617da1e79112ebcbc6c81827c595997281aa180af1335 The Red Hat security contact is secalert@redhat.com . More contact details at https://access.redhat.com/security/team/contact/ .

Share this article