|
erlang (1:24.2.1+dfsg-1ubuntu0.7) jammy-security; urgency=medium
* SECURITY UPDATE: denial of service in the Erlang Port Mapper Daemon
- debian/patches/CVE-2026-42792.patch: epmd: Improve slow-connection
handling in erts/epmd/src/epmd_srv.c.
- CVE-2026-42792
* SECURITY UPDATE: buffer overflow via crafted packet length
- debian/patches/CVE-2026-75538.patch: Avoid signed int overflows in
erts/emulator/beam/packet_parser.c,
erts/emulator/drivers/common/inet_drv.c.
- CVE-2026-75538
* SECURITY UPDATE: buffer overflow in the megaco flex scanner
- debian/patches/CVE-2026-59250.patch: megaco: fix sprintf buffer overflow
in flex scanner in lib/megaco/src/flex/megaco_flex_scanner_drv.flex.src.
- CVE-2026-59250
* SECURITY UPDATE: TLS clients accepted cipher suites they did not offer
- debian/patches/CVE-2026-55953.patch: ssl: Add pre TLS-1.3 client cipher
suite check in lib/ssl/src/ssl_handshake.erl.
- CVE-2026-55953
* SECURITY UPDATE: denial of service via crafted certificate chains
- debian/patches/CVE-2026-58227.patch: ssl: Use digraph to ensure robust
cert chain building. in lib/ssl/src/ssl_certificate.erl,
lib/ssl/test/ssl_cert_SUITE.erl.
- CVE-2026-58227
* SECURITY UPDATE: HTTP request smuggling via conflicting framing headers
- debian/patches/CVE-2026-73812-pre1.patch: Prevent httpd from parsing HTTP
requests when multiple Content-Length headers are present in
lib/inets/src/http_server/httpd_request.erl,
lib/inets/src/http_server/httpd_request_handler.erl,
lib/inets/test/httpd_SUITE.erl.
- debian/patches/CVE-2026-73812.patch: inets: Reject requests with both
Transfer-Encoding and Content-Length in
lib/inets/src/http_server/httpd_internal.hrl,
lib/inets/src/http_server/httpd_request.erl,
lib/inets/test/http_test_lib.erl, lib/inets/test/httpc_SUITE.erl.
- CVE-2026-23941
- CVE-2026-73812
* SECURITY UPDATE: denial of service via malformed chunk sizes
- debian/patches/CVE-2026-69664.patch: inets: Fix rejection of invalid chunk
sizes in lib/inets/src/http_server/httpd_request_handler.erl,
lib/inets/test/httpd_SUITE.erl.
- CVE-2026-69664
* SECURITY UPDATE: denial of service via unbounded chunked request bodies
- debian/patches/CVE-2026-74835.patch: inets: Fix max_body_size to apply to
chunks as we receive them in lib/inets/src/http_lib/http_chunk.erl,
lib/inets/src/http_server/httpd_request_handler.erl,
lib/inets/test/http_format_SUITE.erl.
- CVE-2026-74835
* SECURITY UPDATE: authentication bypass via path equivalence / authentication bypass via inconsistent case handling
- debian/patches/CVE-2026-66835_73270.patch: inets: Canonicalize request
path before mod_auth directory check in
lib/inets/src/http_server/httpd_request.erl,
lib/inets/src/http_server/httpd_util.erl,
lib/inets/src/http_server/mod_alias.erl,
lib/inets/src/http_server/mod_auth.erl.
- CVE-2026-66835
- CVE-2026-73270
* SECURITY UPDATE: denial of service via unlimited simultaneous connections
- debian/patches/CVE-2026-70399.patch: inets: Fix default max_clients in
lib/inets/src/http_lib/http_internal.hrl,
lib/inets/src/http_server/httpd_manager.erl.
- CVE-2026-70399
* SECURITY UPDATE: HTTP request smuggling via header continuation lines
- debian/patches/CVE-2026-66357.patch: inets: Reject obs-fold header
continuation in httpd (RFC 9112) in
lib/inets/src/http_server/httpd_request.erl,
lib/inets/test/httpd_SUITE.erl.
- CVE-2026-66357
* SECURITY UPDATE: HTTP request smuggling via malformed header names
- debian/patches/CVE-2026-73276.patch: inets: Reject headers with whitespace
before colon in httpd in lib/inets/src/http_lib/http_request.erl,
lib/inets/src/http_server/httpd_request.erl,
lib/inets/test/httpd_SUITE.erl.
- debian/patches/CVE-2026-73276-2.patch: httpd: add error handling for
headers with whitespace before colon in
lib/inets/src/http_lib/http_request.erl,
lib/inets/src/http_server/httpd_internal.hrl,
lib/inets/src/http_server/httpd_request.erl.
- CVE-2026-73276
* SECURITY UPDATE: authentication bypass via inconsistent case handling
- debian/patches/CVE-2026-73270-2.patch: inets: Add caseless matching to
mod_security directory lookup in lib/inets/src/http_server/httpd_util.erl,
lib/inets/src/http_server/mod_security.erl.
- CVE-2026-73270
* SECURITY UPDATE: denial of service via incomplete request bodies
- debian/patches/CVE-2026-71380-pre1.patch: inets: Adjust keep_alive_timeout
effective measurement in httpd in
lib/inets/src/http_server/httpd_conf.erl,
lib/inets/src/http_server/httpd_request_handler.erl.
- debian/patches/CVE-2026-71380-pre2.patch: inets: Add httpd option
max_body_read_timeout in lib/inets/src/http_lib/http_internal.hrl,
lib/inets/src/http_server/httpd_conf.erl,
lib/inets/src/http_server/httpd_request_handler.erl.
- debian/patches/CVE-2026-71380-pre3.patch: inets: Send 408 when we hit
min_bytes_per_second floor in
lib/inets/src/http_server/httpd_request_handler.erl.
- debian/patches/CVE-2026-71380.patch: inets: rename max_body_read_timeout
option to request_timeout in lib/inets/src/http_lib/http_internal.hrl,
lib/inets/src/http_server/httpd_conf.erl,
lib/inets/src/http_server/httpd_request_handler.erl.
- debian/patches/CVE-2026-71380-2.patch: Fix dialyzer errors in
httpd_request_handler in
lib/inets/src/http_server/httpd_request_handler.erl.
- CVE-2026-71380
* SECURITY UPDATE: denial of service via unbounded HTTP response headers
- debian/patches/CVE-2026-55951-pre1.patch: OTP-19158 httpc enable options
for async request in lib/inets/src/http_client/httpc.erl,
lib/inets/src/http_client/httpc_handler.erl,
lib/ine
|