[Git][security-tracker-team/security-tracker][master] Add two more erlang issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 3 14:07:14 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a6f6c77f by Salvatore Bonaccorso at 2026-09-03T12:59:17+02:00
Add two more erlang issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1603,7 +1603,12 @@ CVE-2026-61750 (NVIDIA Megatron Bridge contains a vulnerability where an attacke
 CVE-2026-5480
 	REJECTED
 CVE-2026-59696 (Improper Validation of Specified Quantity in Input vulnerability in Er ...)
-	TODO: check
+	- erlang <unfixed>
+	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-8qw4-2chm-mvj2
+	NOTE: https://cna.erlef.org/cves/CVE-2026-59696.html
+	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-59696
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/e3be1cfe9f6cedd0cd20d9905e05601dfb31c8aa (OTP-29.0.6, OTP-28.5.0.6)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/aba0fe8c2d700bf4ac94607cf7f00e53bbe4042d (OTP-27.3.4.17)
 CVE-2026-59681 (A OS command injection vulnerability in yast2-auth-client allows an at ...)
 	TODO: check
 CVE-2026-59680 (An OS command injection vulnerability was found in yast2-users. When d ...)
@@ -1621,7 +1626,12 @@ CVE-2026-58567 (Dell PowerStore contains an OS Command Injection vulnerability.
 CVE-2026-58566 (Dell PowerStore, an Incorrect Authorization vulnerability. A low privi ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-55951 (The Erlang/OTP httpc HTTP client does not enforce a limit on the total ...)
-	TODO: check
+	- erlang <unfixed>
+	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-f9fw-mg7q-4g3x
+	NOTE: https://cna.erlef.org/cves/CVE-2026-55951.html
+	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-55951
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/e3be1cfe9f6cedd0cd20d9905e05601dfb31c8aa (OTP-29.0.6, OTP-28.5.0.6)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/aba0fe8c2d700bf4ac94607cf7f00e53bbe4042d (OTP-27.3.4.17)
 CVE-2026-53682 (An unauthenticated client can query the Security Domain hosts inventor ...)
 	- dogtag-pki <removed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2487511



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a6f6c77f1de6cd1424d1c8a57a3f78341734a35e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a6f6c77f1de6cd1424d1c8a57a3f78341734a35e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/4fc521eb/attachment.htm>


More information about the debian-security-tracker-commits mailing list