[Git][security-tracker-team/security-tracker][master] new erlang issues (fixed in sid)

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Sep 23 16:51:00 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
21b7500a by Moritz Muehlenhoff at 2026-09-23T17:50:52+02:00
new erlang issues (fixed in sid)

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1054,7 +1054,7 @@ CVE-2026-90462 (A flaw was found in SSSD. When configured with the LDAP access p
 CVE-2026-8849 (Use After Free vulnerability in RTI Connext Professional (Security Plu ...)
 	NOT-FOR-US: RTI Connext
 CVE-2026-89422 (Key Exchange without Entity Authentication vulnerability in Erlang/OTP ...)
-	- erlang <unfixed>
+	- erlang 1:29.1.1+dfsg-1
 	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-rgxr-4g4w-j875
 	NOTE: https://cna.erlef.org/cves/CVE-2026-89422.html
 	NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-89422
@@ -1428,9 +1428,14 @@ CVE-2026-70410 (Use of Externally-Controlled Input to Select Classes or Code ('U
 CVE-2026-6922 (The WP Table Builder \u2013 Drag & Drop Table Builder plugin for WordP ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-68956 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
-	TODO: check
+	- erlang 1:29.1.1+dfsg-1
+	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-qhcm-px9c-rvfh
+	NOTE: Introduced by: https://github.com/erlang/otp/commit/84df3d4d0278e21a36a453bfee94799f0df67c2a (OTP-18.1.2)
+	NOTE: Fixed by: https://github.com/erlang/otp/commit/79c2d2be17d902c5f53969b5806b725efda831be (OTP-29.1.1)
 CVE-2026-65634 (Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENT ...)
-	TODO: check
+	- erlang 1:29.1.1+dfsg-1
+	NOTE: https://github.com/erlang/otp/security/advisories/GHSA-qghx-23m5-r55m
+	NOTE: https://github.com/erlang/otp/commit/0fe2c02fdc06fab1c63be9db1a7456993d20f838 (OTP-29.1.1)
 CVE-2026-65179 (NVIDIA NeMo contains a vulnerability in the TabularTokenizer class whe ...)
 	NOT-FOR-US: NVIDIA
 CVE-2026-65178 (NVIDIA NeMo contains a vulnerability in its dataset-loading workflow w ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/21b7500a399e70307a8878c4d5130a8686ae4316

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/21b7500a399e70307a8878c4d5130a8686ae4316
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260923/76d8e8f7/attachment.htm>


More information about the debian-security-tracker-commits mailing list