|
erlang (1:27.3.4.6+dfsg-1ubuntu0.1) resolute-security; urgency=medium
* debian/rules: only replace the javadoc-bundled jQuery/jQuery-UI files
that are actually present. Their location is generated by javadoc and
JDK 23 and later no longer bundle jQuery, so the unconditional ln(1)
calls failed the build on JDK 25.
* SECURITY UPDATE: denial of service in the Erlang Port Mapper Daemon
- debian/patches/CVE-2026-42792.patch: epmd: Improve slow-connection
handling in erts/epmd/src/epmd_srv.c.
- CVE-2026-42792
* SECURITY UPDATE: heap corruption via crafted external term format data
- debian/patches/CVE-2026-55737.patch: erts: Fixes heap pointer corruption
via signed/unsigned mismatch in erts/emulator/beam/external.c.
- CVE-2026-55737
* SECURITY UPDATE: denial of service via crafted external term format data
- debian/patches/CVE-2026-54890.patch: erts: Fix crash on decoding invalid
ETF terms in erts/emulator/beam/external.c,
erts/emulator/test/binary_SUITE.erl.
- CVE-2026-54890
* SECURITY UPDATE: buffer overflow via crafted packet length
- debian/patches/CVE-2026-75538.patch: Avoid signed int overflows in
erts/emulator/beam/packet_parser.c,
erts/emulator/drivers/common/inet_drv.c.
- CVE-2026-75538
* SECURITY UPDATE: buffer overflow in the megaco flex scanner
- debian/patches/CVE-2026-59250.patch: megaco: fix sprintf buffer overflow
in flex scanner in lib/megaco/src/flex/megaco_flex_scanner_drv.flex.src.
- CVE-2026-59250
* SECURITY UPDATE: TLS clients accepted cipher suites they did not offer
- debian/patches/CVE-2026-55953.patch: ssl: Add pre TLS-1.3 client cipher
suite check in lib/ssl/src/ssl_handshake.erl.
- CVE-2026-55953
* SECURITY UPDATE: denial of service via crafted certificate chains
- debian/patches/CVE-2026-58227.patch: ssl: Use digraph to ensure robust
cert chain building. in lib/ssl/src/ssl_certificate.erl,
lib/ssl/test/ssl_cert_SUITE.erl.
- CVE-2026-58227
* SECURITY UPDATE: denial of service via crafted certificate policies
- debian/patches/CVE-2026-59251.patch: public_key: Cap policy tree growth to
prevent DoS in lib/public_key/include/public_key.hrl,
lib/public_key/src/pubkey_cert.erl,
lib/public_key/src/pubkey_policy_tree.erl,
lib/public_key/src/public_key.erl,
lib/public_key/test/pubkey_policy_tree_SUITE.erl,
lib/ssl/src/ssl_handshake.erl.
- CVE-2026-59251
* SECURITY UPDATE: HTTP request smuggling via conflicting framing headers
- debian/patches/CVE-2026-73812-pre1.patch: Prevent httpd from parsing HTTP
requests when multiple Content-Length headers are present in
lib/inets/src/http_server/httpd_request.erl,
lib/inets/src/http_server/httpd_request_handler.erl,
lib/inets/test/httpd_SUITE.erl.
- debian/patches/CVE-2026-73812.patch: inets: Reject requests with both
Transfer-Encoding and Content-Length in
lib/inets/src/http_server/httpd_internal.hrl,
lib/inets/src/http_server/httpd_request.erl,
lib/inets/test/http_test_lib.erl, lib/inets/test/httpc_SUITE.erl.
- CVE-2026-23941
- CVE-2026-73812
* SECURITY UPDATE: denial of service via malformed chunk sizes
- debian/patches/CVE-2026-69664.patch: inets: Fix rejection of invalid chunk
sizes in lib/inets/src/http_server/httpd_request_handler.erl,
lib/inets/test/httpd_SUITE.erl.
- CVE-2026-69664
* SECURITY UPDATE: denial of service via unbounded chunked request bodies
- debian/patches/CVE-2026-74835.patch: inets: Fix max_body_size to apply to
chunks as we receive them in lib/inets/src/http_lib/http_chunk.erl,
lib/inets/src/http_server/httpd_request_handler.erl,
lib/inets/test/http_format_SUITE.erl,
lib/inets/test/httpd_basic_SUITE.erl.
- debian/patches/CVE-2026-74835-2.patch: Fix
httpd_basic_SUITE:chunked_body_size_unbounded/1 testcase for
patch-base-27 in lib/inets/test/httpd_basic_SUITE.erl.
- CVE-2026-74835
* SECURITY UPDATE: authentication bypass via path equivalence / authentication bypass via inconsistent case handling
- debian/patches/CVE-2026-66835_73270.patch: inets: Canonicalize request
path before mod_auth directory check in
lib/inets/src/http_server/httpd_request.erl,
lib/inets/src/http_server/httpd_util.erl,
lib/inets/src/http_server/mod_alias.erl,
lib/inets/src/http_server/mod_auth.erl.
- CVE-2026-66835
- CVE-2026-73270
* SECURITY UPDATE: denial of service via unlimited simultaneous connections
- debian/patches/CVE-2026-70399.patch: inets: Fix default max_clients in
lib/inets/src/http_lib/http_internal.hrl,
lib/inets/src/http_server/httpd_manager.erl,
lib/inets/test/httpd_SUITE.erl, lib/inets/test/httpd_basic_SUITE.erl.
- CVE-2026-70399
* SECURITY UPDATE: HTTP request smuggling via header continuation lines
- debian/patches/CVE-2026-66357.patch: inets: Reject obs-fold header
continuation in httpd (RFC 9112) in
lib/inets/src/http_server/httpd_request.erl,
lib/inets/test/httpd_SUITE.erl.
- CVE-2026-66357
* SECURITY UPDATE: HTTP request smuggling via malformed header names
- debian/patches/CVE-2026-73276.patch: inets: Reject headers with whitespace
before colon in httpd in lib/inets/src/http_lib/http_request.erl,
lib/inets/src/http_server/httpd_request.erl,
lib/inets/test/httpd_SUITE.erl.
- debian/patches/CVE-2026-73276-2.patch: httpd: add error handling for
headers with whitespace before colon in
lib/inets/src/http_lib/http_request.erl,
lib/inets/src/http_server/httpd_internal.hrl,
lib/inets/src/http_server/httpd_request.erl.
- CVE-2026-73276
* SECURITY UPDATE: authentication bypass via inconsistent case handling
- debian/patches/CVE-2026-73270-2.patch: inets: Add caseless matching to
mod_security directory lookup in lib/inets/doc/guides/h
|