CVE-2026-21620
Publication date 20 February 2026
Last updated 8 October 2026
Ubuntu priority
Description
Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tftp_file modules), erlang otp tftp (tftp_file modules) allows Relative Path Traversal. This vulnerability is associated with program files lib/tftp/src/tftp_file.erl, src/tftp_file.erl. This issue affects OTP from OTP 17.0 before OTP 28.3.2, OTP 27.3.4.8 and OTP 26.2.5.17, corresponding to tftp from 1.0 before 1.2.4, 1.2.2.1 and 1.1.1.1; also inets from 5.10 before 7.0.
Read the notes from the security team
Why is this CVE low priority?
This requires an application that misuses the tftp API
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| erlang | 26.04 LTS resolute |
Fixed 1:27.3.4.6+dfsg-1ubuntu0.2
|
| 24.04 LTS noble |
Fixed 1:25.3.2.8+dfsg-1ubuntu4.8
|
|
| 22.04 LTS jammy |
Fixed 1:24.2.1+dfsg-1ubuntu0.8
|
|
| 20.04 LTS focal |
Fixed 1:22.2.7+dfsg-1ubuntu0.5+esm3
|
|
| 18.04 LTS bionic |
Fixed 1:20.2.2+dfsg-1ubuntu2+esm4
|
|
| 16.04 LTS xenial |
Fixed 1:18.3-dfsg-1ubuntu3.1+esm4
|
|
| 14.04 LTS trusty |
Fixed 1:16.b.3-dfsg-1ubuntu2.2+esm3
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialNotes
mdeslaur
Per upstream: "For a system to be vulnerable, the system designer must have used the undescribed {root_dir,RootDir} state as an option under incorrect assumptions. The state value/type is present in the documentation, in a function signature specification, but it is never described. It is only the option's name that may suggest that it could protect against relative path traversal."
Severity score breakdown
CVSS version: CVSS v4.0
Base score
2.3 · Low
Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N