[Pkg-erlang-devel] erlang_29.0.4+dfsg-1_source.changes ACCEPTED into unstable
Debian FTP Masters
ftpmaster at ftp-master.debian.org
Thu Jul 30 11:49:42 BST 2026
Thank you for your contribution to Debian.
Accepted:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Thu, 30 Jul 2026 13:30:50 +0300
Source: erlang
Architecture: source
Version: 1:29.0.4+dfsg-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Erlang Packagers <pkg-erlang-devel at lists.alioth.debian.org>
Changed-By: Sergei Golovan <sgolovan at debian.org>
Closes: 1142985
Changes:
erlang (1:29.0.4+dfsg-1) unstable; urgency=medium
.
* New upstream release.
- Fix CVE-2026-42792: Improper Handling of Exceptional Conditions
vulnerability in Erlang/OTP epmd daemon.
- Fix CVE-2026-47078: Relative Path Traversal vulnerability in Erlang/OTP
stdlib (zip module).
- Fix CVE-2026-54890: Integer Underflow (Wrap or Wraparound) vulnerability
in Erlang/OTP erts.
- Fix CVE-2026-55737: Signed to Unsigned Conversion Error and
Out-of-bounds Write vulnerability in Erlang/OTP erts.
- Fix CVE-2026-55953: The Erlang/OTP ssl TLS and DTLS client does not
verify that the cipher suite selected by the server in ServerHello
was among the suites offered by the client in ClientHello.
- Fix CVE-2026-58227: The Erlang/OTP ssl application does not detect
cycles when reconstructing an incomplete peer certificate chain during
a TLS or DTLS handshake.
- Fix CVE-2026-59250: Buffer overflow in the Erlang/OTP megaco flex
scanner C driver allows a remote unauthenticated attacker to corrupt
the driver's memory.
- Fix CVE-2026-59251: Allocation of resources without limits in Erlang/OTP
public_key certificate path validation allows a remote unauthenticated
attacker to cause denial of service.
Closes: #1142985.
Checksums-Sha1:
1fcb33549922e57f13958134d056ea833a3b8bfb 5002 erlang_29.0.4+dfsg-1.dsc
18fd9b9ac1a1280d415a28349592043c6bd6d6e0 49302664 erlang_29.0.4+dfsg.orig.tar.xz
d6351d4abf193b85b9c7cebb85e816852f4c6e15 62592 erlang_29.0.4+dfsg-1.debian.tar.xz
aae3e4af3f884fa88ce2ac5885b8ec5816e1b133 32348 erlang_29.0.4+dfsg-1_amd64.buildinfo
Checksums-Sha256:
15422d2f6ecaf33a97245144777b51ffa9a47027c84b4aced0fbc53416f730d1 5002 erlang_29.0.4+dfsg-1.dsc
50a470be38a51f8b5f05f4f788063e8823259ad2a2d9c7daa3b8d9b4ecbcc96c 49302664 erlang_29.0.4+dfsg.orig.tar.xz
acbf62e98f89c51c52dc2fedd9984cbacbcbff6fccee33b05496a5698133e84a 62592 erlang_29.0.4+dfsg-1.debian.tar.xz
4ccc509dcce66eb4e8c54eabec233cbedddd5190878608743fe64944384fe62d 32348 erlang_29.0.4+dfsg-1_amd64.buildinfo
Files:
cfea99dd9c950164a22610b041df87a3 5002 interpreters optional erlang_29.0.4+dfsg-1.dsc
1500bd1fbdb8c4425c3928e0979c836b 49302664 interpreters optional erlang_29.0.4+dfsg.orig.tar.xz
fe3e4e9d0cedebe8a01a306afc81463d 62592 interpreters optional erlang_29.0.4+dfsg-1.debian.tar.xz
6f5383c561fafab1cd94e5241bfa3d15 32348 interpreters optional erlang_29.0.4+dfsg-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE/SYPsyDB+ShSnvc4Tyrk60tj54cFAmprKckACgkQTyrk60tj
54ewiBAAoq1gWiJ4E7iCfvcIY19jrvp7J3lvS5IxNZvW66ymKaE6ZSYJAdHiDDWZ
VuFromSTMNc7RVJ0s+DDwr3l1ZYQOzN1weRTMBtf67jgUekUVcflBG0y4U8XuGXI
RGj41xe2ZzucNdWZ7S4vjQzco87QSpcRAZ1cedtWlvfPW5uwEioWYO6gPS0LSytb
m2nAUeDpEWn81DNuJV45IYxG/r3pmm3sBw+j9AA7e7TUA7RVz96oBDZ1gpUDxGjC
lwgtpp2j61N/foLg96YjA2Grqsa9G9KC7sD2T7npjHpJAb/FcxOPhKT+5eRh4WeL
fNBhQ+zOW7hpDefhG5B4WDZOBhSbCl8dEpRP+/Od6BZlNfPUfGS6/QHR1Tcn3em4
waVCDDuU/lOVK+W0X6npNd3qwn9c+T0qmIqfDUC7lNu1hl3Ho9EjRMP7CupgUkj3
oZSDchcTi4wFR0kL8CQ+c1TFaJSM6qXaDwx05pmkcSwKpLpV8GHr0rRgJL/YvUA9
uAXzsgeHFU1CpVP74cODHuuUwbfVTOrvtLGKGDJ0hFWsBpFMcTeV8Dk5pkFR67cH
R0eucWQcb1mekfwksyee3lRbMTKo+EMSmAlyoPzfGxr4Ire+mxy4+iI4T63yLLgN
LVwEgv9dm7w0VQ0xJ0rmF9Da2dK3nktLq4PJj7GNOUZGOrRxocc=
=DqJs
-----END PGP SIGNATURE-----
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-erlang-devel/attachments/20260730/f41144e7/attachment-0001.sig>
More information about the Pkg-erlang-devel
mailing list