Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
This update includes the following RPMs: erlang27: * erlang27-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-asn1-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-common_test-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-compiler-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-crypto-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-debugger-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-dialyzer-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-diameter-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-edoc-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-eldap-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-erl_interface-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-erts-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-et-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-eunit-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-examples-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-ftp-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-gdb-tools-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-inets-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-jinterface-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-kernel-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-megaco-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-mnesia-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-observer-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-odbc-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-os_mon-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-parsetools-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-public_key-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-reltool-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-runtime_tools-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-sasl-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-snmp-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-ssh-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-ssl-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-stdlib-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-syntax_tools-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-tftp-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-tools-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-wx-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-xmerl-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-27.3.4.15-0.1.hum1.src (src)
AI Analysis
Technical Summary
Red Hat issued a security advisory (RHSA-2026:47009) for Red Hat Hardened Images RPMs that includes fixes for multiple CVEs, notably CVE-2026-59251, a denial of service vulnerability in Erlang/OTP's public_key application. The vulnerability arises from improper resource allocation limits during TLS certificate path validation, which can be exploited remotely without authentication by sending crafted X.509 certificate chains. This leads to excessive CPU and memory usage, causing the Erlang Virtual Machine to crash. The advisory lists updated erlang27 RPM packages (version 27.3.4.15-0.1.hum1) for aarch64 and x86_64 architectures that address these issues. Red Hat provides detailed references and encourages applying the update to mitigate the risk.
Potential Impact
The vulnerability allows remote unauthenticated attackers to cause a denial of service by crashing the Erlang VM through resource exhaustion during TLS certificate validation. This impacts availability but does not affect confidentiality or integrity. The advisory rates the severity as critical due to the potential for service disruption. No active exploitation in the wild has been reported.
Mitigation Recommendations
Red Hat has released updated RPM packages (erlang27 version 27.3.4.15-0.1.hum1) that fix the vulnerabilities described. Users should apply these official updates to affected Red Hat Hardened Images to remediate the issue. No alternative mitigations or workarounds are specified in the advisory. Patch status is confirmed as fixed in the provided updated packages.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
This update includes the following RPMs: erlang27: * erlang27-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-asn1-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-common_test-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-compiler-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-crypto-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-debugger-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-dialyzer-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-diameter-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-edoc-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-eldap-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-erl_interface-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-erts-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-et-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-eunit-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-examples-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-ftp-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-gdb-tools-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-inets-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-jinterface-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-kernel-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-megaco-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-mnesia-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-observer-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-odbc-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-os_mon-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-parsetools-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-public_key-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-reltool-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-runtime_tools-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-sasl-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-snmp-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-ssh-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-ssl-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-stdlib-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-syntax_tools-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-tftp-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-tools-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-wx-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-xmerl-27.3.4.15-0.1.hum1 (aarch64, x86_64) * erlang27-27.3.4.15-0.1.hum1.src (src)
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Red Hat issued a security advisory (RHSA-2026:47009) for Red Hat Hardened Images RPMs that includes fixes for multiple CVEs, notably CVE-2026-59251, a denial of service vulnerability in Erlang/OTP's public_key application. The vulnerability arises from improper resource allocation limits during TLS certificate path validation, which can be exploited remotely without authentication by sending crafted X.509 certificate chains. This leads to excessive CPU and memory usage, causing the Erlang Virtual Machine to crash. The advisory lists updated erlang27 RPM packages (version 27.3.4.15-0.1.hum1) for aarch64 and x86_64 architectures that address these issues. Red Hat provides detailed references and encourages applying the update to mitigate the risk.
Potential Impact
The vulnerability allows remote unauthenticated attackers to cause a denial of service by crashing the Erlang VM through resource exhaustion during TLS certificate validation. This impacts availability but does not affect confidentiality or integrity. The advisory rates the severity as critical due to the potential for service disruption. No active exploitation in the wild has been reported.
Mitigation Recommendations
Red Hat has released updated RPM packages (erlang27 version 27.3.4.15-0.1.hum1) that fix the vulnerabilities described. Users should apply these official updates to affected Red Hat Hardened Images to remediate the issue. No alternative mitigations or workarounds are specified in the advisory. Patch status is confirmed as fixed in the provided updated packages.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:47009
- Cve Count
- 3
- Additional Cves
- ["CVE-2026-54890","CVE-2026-59251"]
- State
- PUBLISHED
Threat ID: 6a6ae50c9c2644c7f897f9dc
Added to database: 07/30/2026, 05:45:48 UTC
Last enriched: 08/16/2026, 17:57:35 UTC
Last updated: 09/14/2026, 22:01:34 UTC
Views: 49
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.