[Git][security-tracker-team/security-tracker][master] Track fixed version for erlang issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 30 13:16:53 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6c4575f1 by Salvatore Bonaccorso at 2026-07-30T14:16:28+02:00
Track fixed version for erlang issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3265,7 +3265,7 @@ CVE-2026-59528 (Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipp
 CVE-2026-59527 (Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59251 (Allocation of resources without limits in Erlang/OTP public_key certif ...)
-	- erlang <unfixed> (bug #1142985)
+	- erlang 1:29.0.4+dfsg-1 (bug #1142985)
 	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-622p-qfh6-c352
 	NOTE: https://cna.erlef.org/cves/CVE-2026-59251.html
 	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-59251
@@ -3273,7 +3273,7 @@ CVE-2026-59251 (Allocation of resources without limits in Erlang/OTP public_key
 	NOTE: Fixed by: https://github.com/erlang/otp/commit/f04c6bba38de1cf1b1836a7d9a9fbe239bd939e8 (OTP-27.3.4.15)
 	NOTE: Fixed by: https://github.com/erlang/otp/commit/f8580fc117098c08165f46c26fd0750c5cfb2a90 (OTP-29.0.4, OTP-28.5.0.4)
 CVE-2026-59250 (Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver ...)
-	- erlang <unfixed> (bug #1142985)
+	- erlang 1:29.0.4+dfsg-1 (bug #1142985)
 	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-7xgh-gmgf-q2g7
 	NOTE: https://cna.erlef.org/cves/CVE-2026-59250.html
 	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-59250
@@ -3288,7 +3288,7 @@ CVE-2026-58389 (Allocation of Resources Without Limits or Throttling vulnerabili
 	- thrift <unfixed>
 	NOTE: https://lists.apache.org/thread/ht2mjt8m3vz9v0h5pqzvc4r4nzfxwtrw
 CVE-2026-58227 (The Erlang/OTP ssl application does not detect cycles when reconstruct ...)
-	- erlang <unfixed> (bug #1142985)
+	- erlang 1:29.0.4+dfsg-1 (bug #1142985)
 	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-r5jr-mq46-vmhw
 	NOTE: https://cna.erlef.org/cves/CVE-2026-58227.html
 	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-58227
@@ -3319,7 +3319,7 @@ CVE-2026-55968 (Inefficient Algorithmic Complexity, Allocation of Resources With
 	- thrift <unfixed>
 	NOTE: https://lists.apache.org/thread/gxhhfyr6flr5vzr4qnxm13p6fc41qstp
 CVE-2026-55953 (The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not veri ...)
-	- erlang <unfixed> (bug #1142985)
+	- erlang 1:29.0.4+dfsg-1 (bug #1142985)
 	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-c6cw-pr89-w882
 	NOTE: https://cna.erlef.org/cves/CVE-2026-55953.html
 	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-55953
@@ -3328,7 +3328,7 @@ CVE-2026-55953 (The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does no
 	NOTE: Fixed by: https://github.com/erlang/otp/commit/0a82596d425abe43dc2e0b3d74aa1557ef74051c (OTP-28.5.0.4)
 	NOTE: Fixed by: https://github.com/erlang/otp/commit/064e236414614f9085cbbbd6eacf0e43c02d1b4b (OTP-29.0.4)
 CVE-2026-55737 (Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerabil ...)
-	- erlang <unfixed> (bug #1142985)
+	- erlang 1:29.0.4+dfsg-1 (bug #1142985)
 	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-446w-268v-9462
 	NOTE: https://cna.erlef.org/cves/CVE-2026-55737.html
 	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-55737
@@ -3339,7 +3339,7 @@ CVE-2026-55579 (Pheditor is a single-file editor and file manager written in PHP
 CVE-2026-55578 (Pheditor is a single-file editor and file manager written in PHP. From ...)
 	NOT-FOR-US: Pheditor
 CVE-2026-54890 (Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erl ...)
-	- erlang <unfixed> (bug #1142985)
+	- erlang 1:29.0.4+dfsg-1 (bug #1142985)
 	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-54pw-5645-jh86
 	NOTE: https://cna.erlef.org/cves/CVE-2026-54890.html
 	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-54890
@@ -3392,7 +3392,7 @@ CVE-2026-48051 (Papra is a minimalistic document management and archiving platfo
 CVE-2026-48030 (Pheditor is a single-file editor and file manager written in PHP. From ...)
 	NOT-FOR-US: Pheditor
 CVE-2026-47078 (Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module ...)
-	- erlang <unfixed> (bug #1142985)
+	- erlang 1:29.0.4+dfsg-1 (bug #1142985)
 	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-rf72-wp7h-jg3x
 	NOTE: https://cna.erlef.org/cves/CVE-2026-47078.html
 	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-47078
@@ -3412,7 +3412,7 @@ CVE-2026-43871 (Loop with Unreachable Exit Condition ('Infinite Loop') vulnerabi
 	- thrift <unfixed>
 	NOTE: https://lists.apache.org/thread/l4dwf14zbyqsmkc28c99ojj3t3gg9qby
 CVE-2026-42792 (Improper Handling of Exceptional Conditions vulnerability in Erlang OT ...)
-	- erlang <unfixed> (bug #1142985)
+	- erlang 1:29.0.4+dfsg-1 (bug #1142985)
 	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-h6f3-hx58-xhj6
 	NOTE: https://cna.erlef.org/cves/CVE-2026-42792.html
 	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-42792



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6c4575f116fb11bf08f0852ad4e85880df8eeae7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6c4575f116fb11bf08f0852ad4e85880df8eeae7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260730/ee295188/attachment.htm>


More information about the debian-security-tracker-commits mailing list