[Pkg-erlang-devel] erlang_27.3.4.1+dfsg-1+deb13u3_source.changes ACCEPTED into proposed-updates
Debian FTP Masters
ftpmaster at ftp-master.debian.org
Mon Aug 31 14:47:31 BST 2026
Thank you for your contribution to Debian.
Accepted:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 22 Aug 2026 22:38:30 +0300
Source: erlang
Architecture: source
Version: 1:27.3.4.1+dfsg-1+deb13u3
Distribution: trixie-security
Urgency: medium
Maintainer: Debian Erlang Packagers <pkg-erlang-devel at lists.alioth.debian.org>
Changed-By: Sergei Golovan <sgolovan at debian.org>
Closes: 1139727 1139823 1141414 1142985
Changes:
erlang (1:27.3.4.1+dfsg-1+deb13u3) trixie-security; urgency=medium
.
[ Aron Xu ]
* Add a series of patches by upstream, which fix a set of vulnerabilities:
- Fix CVE-2026-48855: Exposure of Sensitive Information to an Unauthorized
Actor vulnerability in Erlang OTP ssh application (ssh_sftpd module).
- Fix CVE-2026-48856: Sensitive Data Exposure vulnerability in Erlang OTP
inets application (httpc_response module).
- Fix CVE-2026-48858: Server-Side Request Forgery (SSRF) vulnerability in
Erlang/OTP ftp application (ftp_internal module).
- Fix CVE-2026-48859: Observable Timing Discrepancy vulnerability in
Erlang/OTP ssh application (ssh_auth, ssh_options modules).
- Fix CVE-2026-48860: Reliance on IP Address for Authentication
vulnerability in Erlang/OTP ssl application (inet_tls_dist module).
- Fix CVE-2026-49759: Stack-based Buffer Overflow vulnerability in Erlang
OTP erts (inet_drv).
- Fix CVE-2026-49760: Stack-based Buffer Overflow vulnerability in Erlang
OTP (erl_interface).
Closes: #1139727, #1139823.
- Fix CVE-2026-53422: Observable Response Discrepancy vulnerability in
Erlang OTP ssh application (ssh_sftpd module).
- Fix CVE-2026-54886: Loop with Unreachable Exit Condition ('Infinite
Loop') vulnerability in Erlang OTP ssh application (ssh_sftpd module).
- Fix CVE-2026-54887: Use of Default Cryptographic Key vulnerability in
Erlang/OTP ssl application (DTLS server)
- Fix CVE-2026-54891: Improper Enforcement of Message Integrity During
Transmission in a Communication Channel vulnerability in Erlang/OTP ssl
application (tls_gen_connection module).
- Fix CVE-2026-55950: Time-of-check Time-of-use (TOCTOU) race condition
vulnerability in Erlang/OTP ssl application (dtls_packet_demux module).
- Fix CVE-2026-55952: The Erlang/OTP ssl application does not validate
that the PSK identity list and binder list carried in a TLS 1.3
ClientHello pre-shared key extension have equal length before passing
them to the session ticket handler.
Closes: #1141414.
- Fix CVE-2026-42792: Improper Handling of Exceptional Conditions
vulnerability in Erlang/OTP epmd daemon.
- Fix CVE-2026-47078: Relative Path Traversal vulnerability in Erlang/OTP
stdlib (zip module).
- Fix CVE-2026-54890: Integer Underflow (Wrap or Wraparound) vulnerability
in Erlang/OTP erts.
- Fix CVE-2026-55737: Signed to Unsigned Conversion Error and
Out-of-bounds Write vulnerability in Erlang/OTP erts.
- Fix CVE-2026-55953: The Erlang/OTP ssl TLS and DTLS client does not
verify that the cipher suite selected by the server in ServerHello
was among the suites offered by the client in ClientHello.
- Fix CVE-2026-58227: The Erlang/OTP ssl application does not detect
cycles when reconstructing an incomplete peer certificate chain during
a TLS or DTLS handshake.
- Fix CVE-2026-59250: Buffer overflow in the Erlang/OTP megaco flex
scanner C driver allows a remote unauthenticated attacker to corrupt
the driver's memory.
- Fix CVE-2026-59251: Allocation of resources without limits in Erlang/OTP
public_key certificate path validation allows a remote unauthenticated
attacker to cause denial of service.
Closes: #1142985.
- Fix CVE-2026-28808: Incorrect Authorization vulnerability in Erlang/OTP
(inets modules) allows unauthenticated access to CGI scripts.
- Fix CVE-2026-28810: Generation of Predictable Numbers or Identifiers
vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows
DNS Cache Poisoning.
- Fix CVE-2026-32144: Improper Certificate Validation vulnerability in
Erlang/OTP public_key (pubkey_ocsp module) allows OCSP
designated-responder authorization bypass via missing signature
verification.
- Fix CVE-2026-32147: Vulnerability in the SFTP server where file
attributes could be modified outside the configured root directory.
- Fix CVE-2026-42789: Improper Following of a Certificate's Chain of Trust
vulnerability in Erlang/OTP public_key application allows a non-CA
certificate to be accepted as an intermediate issuer.
- Fix CVE-2026-42790: Improper Certificate Validation vulnerability in
Erlang/OTP public_key application allows a DNS nameConstraints bypass
via subject CommonName fallback in TLS hostname verification.
- Fix CVE-2026-42791: Improper Certificate Validation vulnerability in
Erlang/OTP public_key application allows forged OCSP responses signed
with an expired responder certificate to be accepted as valid.
Checksums-Sha1:
259dcf8b869635e210af9ca48e2f0a540b21b7ee 4945 erlang_27.3.4.1+dfsg-1+deb13u3.dsc
c5e31111a88a6175bcdbb333ef2fdf172500a6ce 47613664 erlang_27.3.4.1+dfsg.orig.tar.xz
db36da86edd129fe2d6663642038cb339ab684f6 150788 erlang_27.3.4.1+dfsg-1+deb13u3.debian.tar.xz
c0ff0d2d9a02080791217c5bb413a646a910a015 32481 erlang_27.3.4.1+dfsg-1+deb13u3_amd64.buildinfo
Checksums-Sha256:
698cabb961a0d38b31465cc35195f92085f5c569d5a4b53b3be9f7df110a9ff2 4945 erlang_27.3.4.1+dfsg-1+deb13u3.dsc
0834643ef1e17886d5e334a39527d8429bcf50613b86d59d4757466f32984b7e 47613664 erlang_27.3.4.1+dfsg.orig.tar.xz
3499b90f23dedc9df7634527f06862ab5f1acded5c4b22bf4eab23b2fbd68b7f 150788 erlang_27.3.4.1+dfsg-1+deb13u3.debian.tar.xz
5f87591f0413bc9e5e0df60004676ecbf9c908029801e5dfc76a838220f72cc2 32481 erlang_27.3.4.1+dfsg-1+deb13u3_amd64.buildinfo
Files:
2dc1f345c534e281ca125c2256344238 4945 interpreters optional erlang_27.3.4.1+dfsg-1+deb13u3.dsc
8e316a9e63f5c4167ba34596b146ab35 47613664 interpreters optional erlang_27.3.4.1+dfsg.orig.tar.xz
309623097689889bcbd3483c8185737d 150788 interpreters optional erlang_27.3.4.1+dfsg-1+deb13u3.debian.tar.xz
c1ed916a4d2174a62a417204273a68e0 32481 interpreters optional erlang_27.3.4.1+dfsg-1+deb13u3_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE/SYPsyDB+ShSnvc4Tyrk60tj54cFAmqLNboACgkQTyrk60tj
54cUyQ//QYEBb5KzGh0m3NsbPMfj9XH+fF9IpNpnxWVpKZkztHED958ZUZY9d/mB
49rovT0zfbxNc/ncYSqOBB0ooVD+ehEFX75hLPHMLUABjloOnlqtKjMZ8nT7aMAS
6Ce/hRIfozkHKJe6pZKXMMjx/KirO9dIhbD5JZu7nsvOgUr05doel+OkDKtO5Zj4
ArTWRubhHw2QQ5LOmrhONHRrnRklYl7Y9W/DjaUCkn13xqx44dj5DtOAzJeC8vSc
T3eQXMjsznfZ3k/mCRl3Trdk/TtW6fY4fO+6J5LY/8drZT2meAl90SeVcPuexohj
qA7yYoioXWNHF3HTYsvLy5GTNWS4OCLJcKB0GUYVHlbmuCShSgnu/NlKG31Hm6P/
JVM3JVJ7nDAeNXMAvwXDN2ux6rkuowJa1hSVxiWwstLYSo7YqIQFqz/ODn8/t+wh
5JH4gWxBWt1t5H1ZCFUNmiiIfYfXhxnosrs0iZKqMKJrVib2OeeXe6jtdVbXFIEn
8GQIEiyhIArQXld/r9mtfkEKytGQjPQSc0P5JBScZSL3XsD4K7cMeys8BD+KgN08
mhHMCGwgiDunquSDariY8vlataGISwPMq+i0EVIvXMrRA9fKJP50Mj+HxYTGTHq5
SAlzMg0NjzB1k1r50Dt+jbMy7c9PduC6R8kzdQgUm7TKqUBj8Ds=
=tMMc
-----END PGP SIGNATURE-----
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-erlang-devel/attachments/20260831/11736d2b/attachment.sig>
More information about the Pkg-erlang-devel
mailing list