[Git][security-tracker-team/security-tracker][master] Add another batch of erlang issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 3 12:10:20 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
33b043bc by Salvatore Bonaccorso at 2026-09-03T11:31:48+02:00
Add another batch of erlang issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1504,13 +1504,36 @@ CVE-2026-70409 (Improper Validation of Specified Quantity in Input vulnerability
 	NOTE: Fixed by: https://github.com/erlang/otp/commit/e3be1cfe9f6cedd0cd20d9905e05601dfb31c8aa (OTP-29.0.6, OTP-28.5.0.6)
 	NOTE: Fixed by: https://github.com/erlang/otp/commit/aba0fe8c2d700bf4ac94607cf7f00e53bbe4042d (OTP-27.3.4.17)
 CVE-2026-70405 (Improper Validation of Specified Quantity in Input vulnerability in Er ...)
-	TODO: check
+	- erlang <unfixed>
+	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-q7cq-pfgf-5hr7
+	NOTE: https://cna.erlef.org/cves/CVE-2026-70405.html
+	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-70405
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/e3be1cfe9f6cedd0cd20d9905e05601dfb31c8aa (OTP-29.0.6, OTP-28.5.0.6)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/aba0fe8c2d700bf4ac94607cf7f00e53bbe4042d (OTP-27.3.4.17)
 CVE-2026-70399 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
-	TODO: check
+	- erlang <unfixed>
+	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-pwvh-c689-f8q5
+	NOTE: https://cna.erlef.org/cves/CVE-2026-70399.html
+	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-70399
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/e0050fc00c500a4fa9ba1f594603c787ff6d20b2 (OTP-29.0.6)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/6746dc4e1df5257ad8ac91cbbd167cb8b0274ce7 (OTP-28.5.0.6)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/d94a94c96eb4cccbd6f7d7da5975f0c035b69612 (OTP-27.3.4.17)
 CVE-2026-69664 (Missing Release of Resource after Effective Lifetime vulnerability in  ...)
-	TODO: check
+	- erlang <unfixed>
+	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-mr35-8h7w-w3gq
+	NOTE: https://cna.erlef.org/cves/CVE-2026-69664.html
+	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-69664
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/df1a9ca4666e2fdfc44886bfaae76de086d803f6 (OTP-29.0.6)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/bd4e74348c6be8a49f060da6fd48d43f3a960292 (OTP-28.5.0.6)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/a3adf63078438c86527d704e23282b7721d8ca12 (OTP-27.3.4.17)
 CVE-2026-66835 (Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remo ...)
-	TODO: check
+	- erlang <unfixed>
+	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-r4vv-vc2c-2fw6
+	NOTE: https://cna.erlef.org/cves/CVE-2026-66835.html
+	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-66835
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/9641944a2efbf55bea760f8ff7ba777fe3a0961c (OTP-29.0.6)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/d8878dec0ececc2eab18e47bb18b472f224ca633 (OTP-28.5.0.6)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/bac19eb3dbd96cc49b6d8cabc1c04248bf8c79f6 (OTP-27.3.4.17)
 CVE-2026-66357 (httpd has never implemented obs-fold (RFC 2616 \xa72.2 / RFC 7230 \xa7 ...)
 	TODO: check
 CVE-2026-61779 (NVIDIA Megatron Bridge contains a vulnerability where an attacker coul ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/33b043bcde427b59978b643c05b7998599e72483

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/33b043bcde427b59978b643c05b7998599e72483
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/0fa6bc4f/attachment.htm>


More information about the debian-security-tracker-commits mailing list