[From nobody Sat Sep  5 19:51:06 2026
Received: (at 558199-close) by bugs.debian.org; 5 Sep 2026 18:50:43 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-114.1 required=4.0 tests=ALL_TRUSTED,BAYES_00,
 DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FOURLA,
 FVGT_m_MULTI_ODD,HAS_BUG_NUMBER,MD5_SHA1_SUM,PGPSIGNATURE,
 USER_IN_DKIM_WELCOMELIST autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 92; hammy, 150; neutral, 426; spammy,
 0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK,
 0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--HX-DAK:process-upload,
 0.000-+--UD:debian.tar.xz, 0.000-+--H*r:sk:fasolo.
Return-path: &lt;envelope@ftp-master.debian.org&gt;
Received: from muffat.debian.org ([2607:f8f0:614:1::1274:33]:43432)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1x2vTP-000jJL-1L for 558199-close@bugs.debian.org;
 Sat, 05 Sep 2026 18:50:43 +0000
Received: via submission
 from C=NA, ST=NA, L=Ankh Morpork, O=Debian SMTP, OU=Debian SMTP CA,
 CN=fasolo.debian.org, EMAIL=hostmaster@fasolo.debian.org (verified)
 by muffat.debian.org with esmtps
 (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1x2vTQ-000DVS-1n for 558199-close@bugs.debian.org;
 Sat, 05 Sep 2026 18:50:43 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
 d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type:
 Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID
 :Content-Description:In-Reply-To:References;
 bh=vXzijYDohl5wg6teHSMwSl3b9QYyU6bLDcLLL0jdd9U=; b=pCUo4wpULadsMkj+b7HVOKsxOK
 nWzdRtPMIn5/faKs8RWzTZsnlaiIZ+vGxXNNk22wULA6KrwJ8E0eDeGuWo1BxlcfYYpeKd4B1foAg
 /ZsMPEq+1MGjByAGeIscoQtg9STNFWD420DeQlcxWMYTHHXJuhf/RnRAsAuDEK6cwy6VIDS7j16Fr
 CT3eMsHot4AwNYQrnyCTuVSyzOay1ZWku4r7w16+VzzDO2KHfBD/uJcG773o4KH3CXK4zxeNiZ/Uw
 MQcckKyhAAhR+39lT/e/Cqo8KEAmLfYz9iGrNGVBf+YwvBztp+zfNbYr1tlE1voLcsldo7sdnoo8r
 fcE+KNzQ==;
Received: from dak by fasolo.debian.org with local (Exim 4.98.2)
 (envelope-from &lt;envelope@ftp-master.debian.org&gt;)
 id 1x2vTO-00000009zq0-1xPh; Sat, 05 Sep 2026 18:50:42 +0000
From: Debian FTP Masters &lt;ftpmaster@ftp-master.debian.org&gt;
Reply-To: Sergei Golovan &lt;sgolovan@debian.org&gt;
To: 558199-close@bugs.debian.org
X-DAK: dak process-upload
X-Debian: DAK
X-Debian-Package: erlang
Debian: DAK
Debian-Changes: erlang_29.0.6+dfsg-1_source.changes
Debian-Source: erlang
Debian-Version: 1:29.0.6+dfsg-1
Debian-Architecture: source
Debian-Suite: unstable
Debian-Archive-Action: accept
MIME-Version: 1.0
Subject: Bug#558199: fixed in erlang 1:29.0.6+dfsg-1
Content-Type: multipart/signed; micalg=&quot;pgp-sha256&quot;;
 protocol=&quot;application/pgp-signature&quot;;
 boundary=&quot;===============6852342204781971413==&quot;
Message-Id: &lt;E1x2vTO-00000009zq0-1xPh@fasolo.debian.org&gt;
Date: Sat, 05 Sep 2026 18:50:42 +0000

--===============6852342204781971413==
Content-Type: text/plain; charset=&quot;utf-8&quot;
Content-Transfer-Encoding: quoted-printable

Source: erlang
Source-Version: 1:29.0.6+dfsg-1
Done: Sergei Golovan &lt;sgolovan@debian.org&gt;

We believe that the bug you reported is fixed in the latest version of
erlang, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 558199@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Sergei Golovan &lt;sgolovan@debian.org&gt; (supplier of updated erlang package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 21 Aug 2026 17:34:23 +0300
Source: erlang
Architecture: source
Version: 1:29.0.6+dfsg-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Erlang Packagers &lt;pkg-erlang-devel@lists.alioth.debian.org&gt;
Changed-By: Sergei Golovan &lt;sgolovan@debian.org&gt;
Closes: 558199 999682 1146603
Changes:
 erlang (1:29.0.6+dfsg-1) unstable; urgency=3Dmedium
 .
   * New upstream release.
     - Fix CVE-2026-55951: The Erlang/OTP httpc HTTP client does not enforce
       a limit on the total size of response headers received from a server.
     - Fix CVE-2026-59696: Improper Validation of Specified Quantity in Input
       vulnerability in Erlang/OTP stdlib allows a remote attacker to degrade
       availability by supplying a URI whose port component is a very long run
       of digits.
     - Fix CVE-2026-66835: Path Equivalence vulnerability in Erlang/OTP inets
       httpd allows a remote unauthenticated attacker to read files inside
       a mod_auth protected directory by prefixing the request path with
       an extra slash.
     - Fix CVE-2026-69664: Missing Release of Resource after Effective Lifeti=
me
       vulnerability in Erlang/OTP inets httpd allows an unauthenticated remo=
te
       attacker to cause denial of service by sending a request with a chunked
       body whose chunk-size line is not a hexadecimal number.
     - Fix CVE-2026-70399: Allocation of Resources Without Limits or Throttli=
ng
       vulnerability in Erlang/OTP inets httpd allows an unauthenticated remo=
te
       attacker to cause denial of service by opening and holding open a large
       number of connections.
     - Fix CVE-2026-70405: Improper Validation of Specified Quantity in Input
       vulnerability in Erlang/OTP snmp allows a remote attacker to degrade
       availability by sending an SNMP message containing a BER INTEGER whose
       length field is arbitrarily large.
     - Fix CVE-2026-70409: Improper Validation of Specified Quantity in Input
       vulnerability in Erlang/OTP eldap allows a malicious or compromised LD=
AP
       server to degrade availability by returning a referral URL whose port
       component is a very long run of digits.
     - Fix CVE-2026-71380: Missing Release of Resource after Effective Lifeti=
me
       vulnerability in Erlang/OTP inets httpd allows an unauthenticated remo=
te
       attacker to cause denial of service by sending valid request headers
       with a large Content-Length and then stalling before the body
       is complete.
     - Fix CVE-2026-73270: Improper Handling of Case Sensitivity vulnerability
       in Erlang/OTP inets httpd allows a remote unauthenticated attacker
       to read files inside a mod_auth protected directory by requesting them
       with different casing, on deployments whose filesystem
       is case-insensitive.
     - Fix CVE-2026-73276: Gracefulness code ignored cases that should
       be rejected, resulting in possible HTTP Request Smuggling opportunitie=
s.
     - Fix CVE-2026-73812: httpd function check_header/3 rejects duplicate
       Content-Length (per CVE-2026-23941) but never checks for the TE+CL
       co-presence that RFC 9112 =C2=A76.3 identifies as a probable smuggling
       attempt.
     - Fix CVE-2026-74835: The inets application HTTP server httpd fails
       to enforce a configured body-size limit on chunked request.
     - Fix CVE-2026-74994: The mod_auth module in OTP's inets httpd server,
       when configured with dets or mnesia authentication backends and multip=
le
       directory configuration blocks, collapses all directory blocks into
       a single shared user/group namespace.
     - Fix CVE-2026-75538: An attacker that connects to an open Erlang TCP
       port that uses the inet driver with {packet,4} mode can use a signed
       overflow in an incorrect packet length calculation to overflow
       the receive buffer into the VM allocator area and beyond
       up to about 2 GB.
     Closes: #1146603.
   * Replace dependency of erlang-jinterface on java2-runtime(-headless)
     by dependency on java-runtime(-headless).
   * Add conflict of erlang-doc with erlang-mode version less than 27.0
     because the /usr/lib/erlang/man symlink was moved from the former package
     to the latter.
   * Erlang related manpages are now shipped in erlang-doc under the
     /usr/share/erlang-doc/man hierarchy, which avoids showing non-Erlang
     manpages in Emacs menu (closes: #558199, #999682).
   * Add gbp.conf with pristine-tar directive, which is needed to produce
     the original tarball with empty directories.
Checksums-Sha1:
 2e0b658dd1567fae70cdcb25fbc8234d510e3b00 5002 erlang_29.0.6+dfsg-1.dsc
 777f84b4e984655c5542f874f178d14b60050b7e 49301784 erlang_29.0.6+dfsg.orig.ta=
r.xz
 6a035187b413e8748173c9a3e1d64176f8ac9d28 63716 erlang_29.0.6+dfsg-1.debian.t=
ar.xz
 92bbc1e6cfd0562420b46e09de4db95ad4b6407c 32289 erlang_29.0.6+dfsg-1_amd64.bu=
ildinfo
Checksums-Sha256:
 dfe95edd32300f4127bd01d974625c41da29a3a48113dc5426b6fc56b40dd039 5002 erlang=
_29.0.6+dfsg-1.dsc
 e679fe8262e5ec32701857e7bc8034032090bf6e2ac0565301a7feca4fb0626f 49301784 er=
lang_29.0.6+dfsg.orig.tar.xz
 1cd7a021c8c48a878656b1239afa91c69dd4f1db53d9b97bf4d79f97aa807327 63716 erlan=
g_29.0.6+dfsg-1.debian.tar.xz
 fdc2036ddf41b2b560eef31def1a7393e40888e80144ea3fb88b7a6dc421e4a0 32289 erlan=
g_29.0.6+dfsg-1_amd64.buildinfo
Files:
 766ccde1098c2a268f989a3dfaffef95 5002 interpreters optional erlang_29.0.6+df=
sg-1.dsc
 6d4a3f0c1c4340634ffd7a3daac8f135 49301784 interpreters optional erlang_29.0.=
6+dfsg.orig.tar.xz
 5fbedfa8e66cb2a89af6ecb8668647a8 63716 interpreters optional erlang_29.0.6+d=
fsg-1.debian.tar.xz
 76d16823ead2c706c6940be087943454 32289 interpreters optional erlang_29.0.6+d=
fsg-1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE/SYPsyDB+ShSnvc4Tyrk60tj54cFAmqcXkYACgkQTyrk60tj
54dizg//fD1Hi3jOwrRzRSASoruqGbqaF4+OrvBoy9oJPV8jXqUR0quEndxenixB
H+G8FrY9SChseWP4q5/Mzkh2i5HWvYLNLBdWcmiY4yLunvRMyJ6yly+mwYR8PQB/
qJ7xXtuemVBvMAa7gCmMjeBm5K2a/8UdwWTViVXlVFvssQib3xKNd6ndNtiu4hWD
lD0cjCagPrAbK4AASLvYFmn2A9FHRPndPv5VK8JHxM0aFJlwSoyye2ds8SyPxF6A
LphdPjOP07t8xGkAmhZVrVEsgcAqYKGYC8XzLX3wdijWkpTVyC8mQqUricRzGs3I
ooO2cqqCecpQcT6h2gWHaess74Psnu7cw4dihiN4AAK4fbSCZxnPZce2BTDpwbOi
P7qpO8fJnHJVCxAzFrYN+JsWLWnW9M9DlgHAPRT3rKmoqspL2kZdyQMtibaW/CDp
u8doP4EufhGVHY3NWc5wv0S7tg0QopuMSfpesFyYCXTeUYJU9fXnG/zJ2ZsHEm/S
lmK0LYKLqa8gRR/U4+W2gffHLqaCT3egNUPR5b9H5Lu55xa/XiVmcFlYizQSD1pd
5hDBOx0BwMrxTiRaa11NyFqlHqFYSA09k39fhCb7wuuBHrQx6kR5HZocLjFso+ri
Mienoi/r0R5FK7qShr0/OJ0qWbfe1NfVPRKDpt1cwJ3q5F1KQbg=3D
=3DrEkC
-----END PGP SIGNATURE-----


--===============6852342204781971413==
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCapxkggAKCRCb9qggYcy5
IbgSAQDjEh3Pq5maZ9r4kJkR4dslu1M6beSLrpNSot06/I5N8wEA2iXx9fN5Lbci
1f4SzkYgfAV6nfESr0ElAvkUYff0yA4=
=DoVQ
-----END PGP SIGNATURE-----

--===============6852342204781971413==--
]