[Pkg-erlang-devel] erlang_29.0.6+dfsg-1_source.changes ACCEPTED into unstable

Debian FTP Masters ftpmaster at ftp-master.debian.org
Sat Sep 5 19:50:42 BST 2026


Thank you for your contribution to Debian.



Accepted:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 21 Aug 2026 17:34:23 +0300
Source: erlang
Architecture: source
Version: 1:29.0.6+dfsg-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Erlang Packagers <pkg-erlang-devel at lists.alioth.debian.org>
Changed-By: Sergei Golovan <sgolovan at debian.org>
Closes: 558199 999682 1146603
Changes:
 erlang (1:29.0.6+dfsg-1) unstable; urgency=medium
 .
   * New upstream release.
     - Fix CVE-2026-55951: The Erlang/OTP httpc HTTP client does not enforce
       a limit on the total size of response headers received from a server.
     - Fix CVE-2026-59696: Improper Validation of Specified Quantity in Input
       vulnerability in Erlang/OTP stdlib allows a remote attacker to degrade
       availability by supplying a URI whose port component is a very long run
       of digits.
     - Fix CVE-2026-66835: Path Equivalence vulnerability in Erlang/OTP inets
       httpd allows a remote unauthenticated attacker to read files inside
       a mod_auth protected directory by prefixing the request path with
       an extra slash.
     - Fix CVE-2026-69664: Missing Release of Resource after Effective Lifetime
       vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote
       attacker to cause denial of service by sending a request with a chunked
       body whose chunk-size line is not a hexadecimal number.
     - Fix CVE-2026-70399: Allocation of Resources Without Limits or Throttling
       vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote
       attacker to cause denial of service by opening and holding open a large
       number of connections.
     - Fix CVE-2026-70405: Improper Validation of Specified Quantity in Input
       vulnerability in Erlang/OTP snmp allows a remote attacker to degrade
       availability by sending an SNMP message containing a BER INTEGER whose
       length field is arbitrarily large.
     - Fix CVE-2026-70409: Improper Validation of Specified Quantity in Input
       vulnerability in Erlang/OTP eldap allows a malicious or compromised LDAP
       server to degrade availability by returning a referral URL whose port
       component is a very long run of digits.
     - Fix CVE-2026-71380: Missing Release of Resource after Effective Lifetime
       vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote
       attacker to cause denial of service by sending valid request headers
       with a large Content-Length and then stalling before the body
       is complete.
     - Fix CVE-2026-73270: Improper Handling of Case Sensitivity vulnerability
       in Erlang/OTP inets httpd allows a remote unauthenticated attacker
       to read files inside a mod_auth protected directory by requesting them
       with different casing, on deployments whose filesystem
       is case-insensitive.
     - Fix CVE-2026-73276: Gracefulness code ignored cases that should
       be rejected, resulting in possible HTTP Request Smuggling opportunities.
     - Fix CVE-2026-73812: httpd function check_header/3 rejects duplicate
       Content-Length (per CVE-2026-23941) but never checks for the TE+CL
       co-presence that RFC 9112 §6.3 identifies as a probable smuggling
       attempt.
     - Fix CVE-2026-74835: The inets application HTTP server httpd fails
       to enforce a configured body-size limit on chunked request.
     - Fix CVE-2026-74994: The mod_auth module in OTP's inets httpd server,
       when configured with dets or mnesia authentication backends and multiple
       directory configuration blocks, collapses all directory blocks into
       a single shared user/group namespace.
     - Fix CVE-2026-75538: An attacker that connects to an open Erlang TCP
       port that uses the inet driver with {packet,4} mode can use a signed
       overflow in an incorrect packet length calculation to overflow
       the receive buffer into the VM allocator area and beyond
       up to about 2 GB.
     Closes: #1146603.
   * Replace dependency of erlang-jinterface on java2-runtime(-headless)
     by dependency on java-runtime(-headless).
   * Add conflict of erlang-doc with erlang-mode version less than 27.0
     because the /usr/lib/erlang/man symlink was moved from the former package
     to the latter.
   * Erlang related manpages are now shipped in erlang-doc under the
     /usr/share/erlang-doc/man hierarchy, which avoids showing non-Erlang
     manpages in Emacs menu (closes: #558199, #999682).
   * Add gbp.conf with pristine-tar directive, which is needed to produce
     the original tarball with empty directories.
Checksums-Sha1:
 2e0b658dd1567fae70cdcb25fbc8234d510e3b00 5002 erlang_29.0.6+dfsg-1.dsc
 777f84b4e984655c5542f874f178d14b60050b7e 49301784 erlang_29.0.6+dfsg.orig.tar.xz
 6a035187b413e8748173c9a3e1d64176f8ac9d28 63716 erlang_29.0.6+dfsg-1.debian.tar.xz
 92bbc1e6cfd0562420b46e09de4db95ad4b6407c 32289 erlang_29.0.6+dfsg-1_amd64.buildinfo
Checksums-Sha256:
 dfe95edd32300f4127bd01d974625c41da29a3a48113dc5426b6fc56b40dd039 5002 erlang_29.0.6+dfsg-1.dsc
 e679fe8262e5ec32701857e7bc8034032090bf6e2ac0565301a7feca4fb0626f 49301784 erlang_29.0.6+dfsg.orig.tar.xz
 1cd7a021c8c48a878656b1239afa91c69dd4f1db53d9b97bf4d79f97aa807327 63716 erlang_29.0.6+dfsg-1.debian.tar.xz
 fdc2036ddf41b2b560eef31def1a7393e40888e80144ea3fb88b7a6dc421e4a0 32289 erlang_29.0.6+dfsg-1_amd64.buildinfo
Files:
 766ccde1098c2a268f989a3dfaffef95 5002 interpreters optional erlang_29.0.6+dfsg-1.dsc
 6d4a3f0c1c4340634ffd7a3daac8f135 49301784 interpreters optional erlang_29.0.6+dfsg.orig.tar.xz
 5fbedfa8e66cb2a89af6ecb8668647a8 63716 interpreters optional erlang_29.0.6+dfsg-1.debian.tar.xz
 76d16823ead2c706c6940be087943454 32289 interpreters optional erlang_29.0.6+dfsg-1_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE/SYPsyDB+ShSnvc4Tyrk60tj54cFAmqcXkYACgkQTyrk60tj
54dizg//fD1Hi3jOwrRzRSASoruqGbqaF4+OrvBoy9oJPV8jXqUR0quEndxenixB
H+G8FrY9SChseWP4q5/Mzkh2i5HWvYLNLBdWcmiY4yLunvRMyJ6yly+mwYR8PQB/
qJ7xXtuemVBvMAa7gCmMjeBm5K2a/8UdwWTViVXlVFvssQib3xKNd6ndNtiu4hWD
lD0cjCagPrAbK4AASLvYFmn2A9FHRPndPv5VK8JHxM0aFJlwSoyye2ds8SyPxF6A
LphdPjOP07t8xGkAmhZVrVEsgcAqYKGYC8XzLX3wdijWkpTVyC8mQqUricRzGs3I
ooO2cqqCecpQcT6h2gWHaess74Psnu7cw4dihiN4AAK4fbSCZxnPZce2BTDpwbOi
P7qpO8fJnHJVCxAzFrYN+JsWLWnW9M9DlgHAPRT3rKmoqspL2kZdyQMtibaW/CDp
u8doP4EufhGVHY3NWc5wv0S7tg0QopuMSfpesFyYCXTeUYJU9fXnG/zJ2ZsHEm/S
lmK0LYKLqa8gRR/U4+W2gffHLqaCT3egNUPR5b9H5Lu55xa/XiVmcFlYizQSD1pd
5hDBOx0BwMrxTiRaa11NyFqlHqFYSA09k39fhCb7wuuBHrQx6kR5HZocLjFso+ri
Mienoi/r0R5FK7qShr0/OJ0qWbfe1NfVPRKDpt1cwJ3q5F1KQbg=
=rEkC
-----END PGP SIGNATURE-----

-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 228 bytes
Desc: not available
URL: <http://alioth-lists.debian.net/pipermail/pkg-erlang-devel/attachments/20260905/63e13098/attachment.sig>


More information about the Pkg-erlang-devel mailing list