Bugs fixes in "erlang"
| Origin | Bug number | Title | Date fixed |
|---|---|---|---|
| CVE | CVE-2026-89422 | Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the | 2026-10-08 |
| CVE | CVE-2026-68956 | Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote attacker to exhaust node memory b | 2026-10-08 |
| CVE | CVE-2026-65634 | Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause denial of servi | 2026-10-08 |
| CVE | CVE-2026-74994 | The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blo | 2026-10-08 |
| CVE | CVE-2026-47078 | Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module) allows writing files outside the intended extraction directory via a crafted | 2026-10-08 |
| CVE | CVE-2026-55952 | The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientHello pre-shared key extension | 2026-10-08 |
| CVE | CVE-2026-54891 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Erlang/OTP ssl (tls_gen_connection module) | 2026-10-08 |
| CVE | CVE-2026-54887 | Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl (DTLS server) allows predictable DTLS cookie computation during the startup window, | 2026-10-08 |
| CVE | CVE-2026-54886 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to render | 2026-10-08 |
| CVE | CVE-2026-53422 | Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to enumerate the existence of fi | 2026-10-08 |
| CVE | CVE-2026-49760 | Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow. This vulnerability is associated with pr | 2026-10-08 |
| CVE | CVE-2026-49759 | Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a c | 2026-10-08 |
| CVE | CVE-2026-48858 | Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and SSRF via an unvalidated PASV r | 2026-10-08 |
| CVE | CVE-2026-48856 | Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data. The httpc client forwards | 2026-10-08 |
| CVE | CVE-2026-48855 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery. The SSH_FXP_REA | 2026-10-08 |
| CVE | CVE-2026-42790 | Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via s | 2026-10-08 |
| CVE | CVE-2026-42789 | Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be ac | 2026-10-08 |
| CVE | CVE-2026-32147 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authentic | 2026-10-08 |
| CVE | CVE-2026-28810 | Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache Poisoning. The buil | 2026-10-08 |
| CVE | CVE-2026-28808 | Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when se | 2026-10-08 |
About
-
Send Feedback to @ubuntu_updates