|
erlang (1:24.2.1+dfsg-1ubuntu0.8) jammy-security; urgency=medium
* debian/patches/CVE-2022-37026-1.patch: call
ssl_gen_statem:handle_own_alert/3, the only arity that exists in this
version, instead of a non-existent handle_own_alert/4, so unexpected
application data and certificate verify errors raise a TLS/DTLS alert
instead of crashing the connection process with undef, in
lib/ssl/src/dtls_connection.erl, lib/ssl/src/tls_connection.erl,
lib/ssl/src/tls_gen_connection.erl.
* SECURITY UPDATE: Path Traversal
- debian/patches/CVE-2026-21620-1.patch: Validate initial options in
lib/tftp/src/tftp_file.erl.
- debian/patches/CVE-2026-21620-2.patch: Rewrite old style catch in
lib/tftp/src/tftp_file.erl.
- debian/patches/CVE-2026-21620-3.patch: Fix typos in
lib/tftp/src/tftp_file.erl.
- debian/patches/CVE-2026-21620-4.patch: Fix an incorrect type and a few
bugs in lib/tftp/src/tftp_file.erl.
- CVE-2026-21620
* SECURITY UPDATE: Path Traversal
- debian/patches/CVE-2026-23942.patch: ssh: Fix path traversal vulnerability
in ssh_sftpd root directory validation in lib/ssh/src/ssh_sftpd.erl.
- CVE-2026-23942
* SECURITY UPDATE: Denial of Service
- debian/patches/CVE-2026-23943.patch: Disable zlib by default and limit
size of decompressed data in lib/ssh/src/ssh_connection_handler.erl,
lib/ssh/src/ssh_transport.erl.
- CVE-2026-23943
* SECURITY UPDATE: Authentication Bypass
- debian/patches/CVE-2026-28808.patch: inets: Check script_alias when using
mod_auth in lib/inets/src/http_server/mod_alias.erl.
- CVE-2026-28808
* SECURITY UPDATE: DNS Cache Poisoning
- debian/patches/CVE-2026-28810-pre1.patch: Use case insensitive domain
compare in lib/kernel/src/inet_db.erl.
- debian/patches/CVE-2026-28810-pre2.patch: Make domain name comparison
ignore trailing dot in lib/kernel/src/inet_db.erl.
- debian/patches/CVE-2026-28810-1.patch: Randomize `inet_res` transaction ID
and source port number in lib/kernel/doc/src/inet_res.xml,
lib/kernel/src/gen_udp.erl, lib/kernel/src/inet.erl,
lib/kernel/src/inet6_udp.erl, lib/kernel/src/inet_db.erl,
lib/kernel/src/inet_dns.erl, lib/kernel/src/inet_res.erl,
lib/kernel/src/inet_udp.erl, lib/kernel/test/inet_res_SUITE.erl.
- debian/patches/CVE-2026-28810-2.patch: Update after feedback in
lib/kernel/src/gen_udp.erl, lib/kernel/src/inet.erl,
lib/kernel/src/inet6_sctp.erl, lib/kernel/src/inet_db.erl,
lib/kernel/src/inet_dns.erl, lib/kernel/src/inet_res.erl,
lib/kernel/src/inet_sctp.erl.
- debian/patches/CVE-2026-28810-3.patch: Fix handling of truncation bit vs.
truncated sections in lib/kernel/src/inet_dns.erl,
lib/kernel/src/inet_res.erl, lib/kernel/test/inet_res_SUITE.erl.
- debian/patches/CVE-2026-28810-4.patch: Do not drop random mode after
getting econnrefused in lib/kernel/src/inet_res.erl.
- CVE-2026-28810
* SECURITY UPDATE: Path Traversal
- debian/patches/CVE-2026-32147.patch: Fix root escape vulnerability in
SSH_FXP_FSETSTAT in lib/ssh/src/ssh_sftpd.erl.
- CVE-2026-32147
* SECURITY UPDATE: Certificate Validation Bypass
- debian/patches/CVE-2026-42789.patch: public_key: Update to stricter check
as clearly defined in RFC 5280 in lib/public_key/src/pubkey_cert.erl.
- CVE-2026-42789
* SECURITY UPDATE: Certificate Validation Bypass
- debian/patches/CVE-2026-42790-1.patch: public_key: Adhere to RFC 9525 in
lib/public_key/src/public_key.erl.
- debian/patches/CVE-2026-42790-2.patch: public_key: Add new error in
lib/public_key/doc/src/public_key.xml, lib/public_key/src/pubkey_cert.erl,
lib/public_key/test/pkits_SUITE.erl.
- debian/patches/CVE-2026-42790-3.patch: ssl: Improve error handling due to
public_key updates. in lib/ssl/src/ssl_handshake.erl.
- CVE-2026-42790
* SECURITY UPDATE: Information Disclosure
- debian/patches/CVE-2026-48855.patch: Fix absolute path leak from
SSH_FXP_READLINK in lib/ssh/src/ssh_sftpd.erl.
- CVE-2026-48855
* SECURITY UPDATE: Information Disclosure
- debian/patches/CVE-2026-48856.patch: inets/httpc: strip sensitive headers
on cross-origin redirect in lib/inets/src/http_client/httpc_response.erl.
- CVE-2026-48856
* SECURITY UPDATE: Server-Side Request Forgery
- debian/patches/CVE-2026-48858.patch: ftp: validate PASV response IP
against control connection peer in lib/ftp/src/ftp.erl.
- CVE-2026-48858
* SECURITY UPDATE: Denial of Service
- debian/patches/CVE-2026-49759-1.patch: Protect the output term buffer from
overflow in erts/emulator/drivers/common/inet_drv.c.
- debian/patches/CVE-2026-49759-2.patch: Rewrite error parse loop to handle
all lengths in erts/emulator/drivers/common/inet_drv.c.
- CVE-2026-49759
* SECURITY UPDATE: Buffer Overflow
- debian/patches/CVE-2026-49760.patch: erl_interface: Fix stack overflow in
ei_s_print_term in lib/erl_interface/src/misc/ei_printterm.c,
lib/erl_interface/test/ei_print_SUITE_data/ei_print_test.c.
- CVE-2026-49760
* SECURITY UPDATE: Information Disclosure
- debian/patches/CVE-2026-53422.patch: Fix realpath path existence oracle in
lib/ssh/src/ssh_sftpd.erl.
- CVE-2026-53422
* SECURITY UPDATE: Denial of Service
- debian/patches/CVE-2026-54886.patch: Fix extended data infinite loop in
sftpd in lib/ssh/src/ssh_sftpd.erl, lib/ssh/test/ssh_sftpd_SUITE.erl.
- CVE-2026-54886
* SECURITY UPDATE: Security Bypass
- debian/patches/CVE-2026-54887.patch: ssl: Avoid cookie forgery during
setup up window in lib/ssl/src/dtls_connection.erl.
- CVE-2026-54887
* SECURITY UPDATE: Plaintext Injection
- debian/patches/CVE-2026-54891.patch: ssl: TLS Client hardening in
lib/ssl/src/tls_gen_connection.erl.
- CVE-2026-54891
* SECURITY UPDATE: Denial of Service
- debian/p
|
| CVE-2022-37026 |
In Erlang/OTP before 23.3.4.15, 24.x before 24.3.4.2, and 25.x before 25.0.2, there is a Client Authentication Bypass in certain client-certification |
| CVE-2026-21620 |
Relative Path Traversal, Improper Isolation or Compartmentalization vulnerability in erlang otp erlang/otp (tftp_file modules), erlang otp inets (tft |
| CVE-2026-23942 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP (ssh_sftpd module) allows Path Traversal. |
| CVE-2026-23943 |
Improper Handling of Highly Compressed Data (Compression Bomb) vulnerability in Erlang OTP ssh (ssh_transport modules) allows Denial of Service via R |
| CVE-2026-28808 |
Incorrect Authorization vulnerability in Erlang OTP (inets modules) allows unauthenticated access to CGI scripts protected by directory rules when se |
| CVE-2026-28810 |
Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache Poisoning. The buil |
| CVE-2026-32147 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authentic |
| CVE-2026-42789 |
Improper Following of a Certificate's Chain of Trust vulnerability in Erlang OTP public_key (pubkey_cert module) allows a non-CA certificate to be ac |
| CVE-2026-42790 |
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via s |
| CVE-2026-48855 |
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery. The SSH_FXP_REA |
| CVE-2026-48856 |
Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data. The httpc client forwards |
| CVE-2026-48858 |
Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and SSRF via an unvalidated PASV r |
| CVE-2026-49759 |
Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a c |
| CVE-2026-49760 |
Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow. This vulnerability is associated with pr |
| CVE-2026-53422 |
Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to enumerate the existence of fi |
| CVE-2026-54886 |
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to render |
| CVE-2026-54887 |
Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl (DTLS server) allows predictable DTLS cookie computation during the startup window, |
| CVE-2026-54891 |
Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Erlang/OTP ssl (tls_gen_connection module) |
| CVE-2026-55952 |
The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientHello pre-shared key extension |
| CVE-2026-47078 |
Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module) allows writing files outside the intended extraction directory via a crafted |
| CVE-2026-74994 |
The mod_auth module in OTP's inets httpd server, when configured with dets or mnesia authentication backends and multiple directory configuration blo |
| CVE-2026-65634 |
Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause denial of servi |
| CVE-2026-68956 |
Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote attacker to exhaust node memory b |
| CVE-2026-89422 |
Key Exchange without Entity Authentication vulnerability in Erlang/OTP ssl allows a peer that answers a TLS 1.3 client connection to impersonate the |
|