-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 22 Aug 2026 22:38:30 +0300
Source: erlang
Architecture: source
Version: 1:27.3.4.1+dfsg-1+deb13u3
Distribution: trixie-security
Urgency: medium
Maintainer: Debian Erlang Packagers <[email protected]>
Changed-By: Sergei Golovan <[email protected]>
Closes: 1139727 1139823 1141414 1142985
Changes:
 erlang (1:27.3.4.1+dfsg-1+deb13u3) trixie-security; urgency=medium
 .
   [ Aron Xu ]
    * Add a series of patches by upstream, which fix a set of vulnerabilities:
     - Fix CVE-2026-48855: Exposure of Sensitive Information to an Unauthorized
       Actor vulnerability in Erlang OTP ssh application (ssh_sftpd module).
     - Fix CVE-2026-48856: Sensitive Data Exposure vulnerability in Erlang OTP
       inets application (httpc_response module).
     - Fix CVE-2026-48858: Server-Side Request Forgery (SSRF) vulnerability in
       Erlang/OTP ftp application (ftp_internal module).
     - Fix CVE-2026-48859: Observable Timing Discrepancy vulnerability in
       Erlang/OTP ssh application (ssh_auth, ssh_options modules).
     - Fix CVE-2026-48860: Reliance on IP Address for Authentication
       vulnerability in Erlang/OTP ssl application (inet_tls_dist module).
     - Fix CVE-2026-49759: Stack-based Buffer Overflow vulnerability in Erlang
       OTP erts (inet_drv).
     - Fix CVE-2026-49760: Stack-based Buffer Overflow vulnerability in Erlang
       OTP (erl_interface).
       Closes: #1139727, #1139823.
     - Fix CVE-2026-53422: Observable Response Discrepancy vulnerability in
       Erlang OTP ssh application (ssh_sftpd module).
     - Fix CVE-2026-54886: Loop with Unreachable Exit Condition ('Infinite
       Loop') vulnerability in Erlang OTP ssh application (ssh_sftpd module).
     - Fix CVE-2026-54887: Use of Default Cryptographic Key vulnerability in
       Erlang/OTP ssl application (DTLS server)
     - Fix CVE-2026-54891: Improper Enforcement of Message Integrity During
       Transmission in a Communication Channel vulnerability in Erlang/OTP ssl
       application (tls_gen_connection module).
     - Fix CVE-2026-55950: Time-of-check Time-of-use (TOCTOU) race condition
     vulnerability in Erlang/OTP ssl application (dtls_packet_demux module).
     - Fix CVE-2026-55952: The Erlang/OTP ssl application does not validate
       that the PSK identity list and binder list carried in a TLS 1.3
       ClientHello pre-shared key extension have equal length before passing
       them to the session ticket handler.
       Closes: #1141414.
     - Fix CVE-2026-42792: Improper Handling of Exceptional Conditions
       vulnerability in Erlang/OTP epmd daemon.
     - Fix CVE-2026-47078: Relative Path Traversal vulnerability in Erlang/OTP
       stdlib (zip module).
     - Fix CVE-2026-54890: Integer Underflow (Wrap or Wraparound) vulnerability
       in Erlang/OTP erts.
     - Fix CVE-2026-55737: Signed to Unsigned Conversion Error and
       Out-of-bounds Write vulnerability in Erlang/OTP erts.
     - Fix CVE-2026-55953: The Erlang/OTP ssl TLS and DTLS client does not
       verify that the cipher suite selected by the server in ServerHello
       was among the suites offered by the client in ClientHello.
     - Fix CVE-2026-58227: The Erlang/OTP ssl application does not detect
       cycles when reconstructing an incomplete peer certificate chain during
       a TLS or DTLS handshake.
     - Fix CVE-2026-59250: Buffer overflow in the Erlang/OTP megaco flex
       scanner C driver allows a remote unauthenticated attacker to corrupt
       the driver's memory.
     - Fix CVE-2026-59251: Allocation of resources without limits in Erlang/OTP
       public_key certificate path validation allows a remote unauthenticated
       attacker to cause denial of service.
       Closes: #1142985.
     - Fix CVE-2026-28808: Incorrect Authorization vulnerability in Erlang/OTP
       (inets modules) allows unauthenticated access to CGI scripts.
     - Fix CVE-2026-28810: Generation of Predictable Numbers or Identifiers
       vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows
       DNS Cache Poisoning.
     - Fix CVE-2026-32144: Improper Certificate Validation vulnerability in
       Erlang/OTP public_key (pubkey_ocsp module) allows OCSP
       designated-responder authorization bypass via missing signature
       verification.
     - Fix CVE-2026-32147: Vulnerability in the SFTP server where file
       attributes could be modified outside the configured root directory.
     - Fix CVE-2026-42789: Improper Following of a Certificate's Chain of Trust
       vulnerability in Erlang/OTP public_key application allows a non-CA
       certificate to be accepted as an intermediate issuer.
     - Fix CVE-2026-42790: Improper Certificate Validation vulnerability in
       Erlang/OTP public_key application allows a DNS nameConstraints bypass
       via subject CommonName fallback in TLS hostname verification.
     - Fix CVE-2026-42791: Improper Certificate Validation vulnerability in
       Erlang/OTP public_key application allows forged OCSP responses signed
       with an expired responder certificate to be accepted as valid.
Checksums-Sha1:
 259dcf8b869635e210af9ca48e2f0a540b21b7ee 4945 
erlang_27.3.4.1+dfsg-1+deb13u3.dsc
 c5e31111a88a6175bcdbb333ef2fdf172500a6ce 47613664 
erlang_27.3.4.1+dfsg.orig.tar.xz
 db36da86edd129fe2d6663642038cb339ab684f6 150788 
erlang_27.3.4.1+dfsg-1+deb13u3.debian.tar.xz
 c0ff0d2d9a02080791217c5bb413a646a910a015 32481 
erlang_27.3.4.1+dfsg-1+deb13u3_amd64.buildinfo
Checksums-Sha256:
 698cabb961a0d38b31465cc35195f92085f5c569d5a4b53b3be9f7df110a9ff2 4945 
erlang_27.3.4.1+dfsg-1+deb13u3.dsc
 0834643ef1e17886d5e334a39527d8429bcf50613b86d59d4757466f32984b7e 47613664 
erlang_27.3.4.1+dfsg.orig.tar.xz
 3499b90f23dedc9df7634527f06862ab5f1acded5c4b22bf4eab23b2fbd68b7f 150788 
erlang_27.3.4.1+dfsg-1+deb13u3.debian.tar.xz
 5f87591f0413bc9e5e0df60004676ecbf9c908029801e5dfc76a838220f72cc2 32481 
erlang_27.3.4.1+dfsg-1+deb13u3_amd64.buildinfo
Files:
 2dc1f345c534e281ca125c2256344238 4945 interpreters optional 
erlang_27.3.4.1+dfsg-1+deb13u3.dsc
 8e316a9e63f5c4167ba34596b146ab35 47613664 interpreters optional 
erlang_27.3.4.1+dfsg.orig.tar.xz
 309623097689889bcbd3483c8185737d 150788 interpreters optional 
erlang_27.3.4.1+dfsg-1+deb13u3.debian.tar.xz
 c1ed916a4d2174a62a417204273a68e0 32481 interpreters optional 
erlang_27.3.4.1+dfsg-1+deb13u3_amd64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE/SYPsyDB+ShSnvc4Tyrk60tj54cFAmqLNboACgkQTyrk60tj
54cUyQ//QYEBb5KzGh0m3NsbPMfj9XH+fF9IpNpnxWVpKZkztHED958ZUZY9d/mB
49rovT0zfbxNc/ncYSqOBB0ooVD+ehEFX75hLPHMLUABjloOnlqtKjMZ8nT7aMAS
6Ce/hRIfozkHKJe6pZKXMMjx/KirO9dIhbD5JZu7nsvOgUr05doel+OkDKtO5Zj4
ArTWRubhHw2QQ5LOmrhONHRrnRklYl7Y9W/DjaUCkn13xqx44dj5DtOAzJeC8vSc
T3eQXMjsznfZ3k/mCRl3Trdk/TtW6fY4fO+6J5LY/8drZT2meAl90SeVcPuexohj
qA7yYoioXWNHF3HTYsvLy5GTNWS4OCLJcKB0GUYVHlbmuCShSgnu/NlKG31Hm6P/
JVM3JVJ7nDAeNXMAvwXDN2ux6rkuowJa1hSVxiWwstLYSo7YqIQFqz/ODn8/t+wh
5JH4gWxBWt1t5H1ZCFUNmiiIfYfXhxnosrs0iZKqMKJrVib2OeeXe6jtdVbXFIEn
8GQIEiyhIArQXld/r9mtfkEKytGQjPQSc0P5JBScZSL3XsD4K7cMeys8BD+KgN08
mhHMCGwgiDunquSDariY8vlataGISwPMq+i0EVIvXMrRA9fKJP50Mj+HxYTGTHq5
SAlzMg0NjzB1k1r50Dt+jbMy7c9PduC6R8kzdQgUm7TKqUBj8Ds=
=tMMc
-----END PGP SIGNATURE-----

Attachment: pgpg04x5SYuKL.pgp
Description: PGP signature

Reply via email to