UbuntuUpdates.org

Package "erlang-ssl"

Name: erlang-ssl

Description:

Erlang/OTP implementation of SSL

Latest version: 1:27.3.4.6+dfsg-1ubuntu0.1
Release: resolute (26.04)
Level: updates
Repository: main
Head package: erlang
Homepage: http://www.erlang.org/

Links


Download "erlang-ssl"


Other versions of "erlang-ssl" in Resolute

Repository Area Version
base main 1:27.3.4.6+dfsg-1
security main 1:27.3.4.6+dfsg-1ubuntu0.1

Changelog

Version: 1:27.3.4.6+dfsg-1ubuntu0.1 2026-09-28 04:07:20 UTC

erlang (1:27.3.4.6+dfsg-1ubuntu0.1) resolute-security; urgency=medium

  * debian/rules: only replace the javadoc-bundled jQuery/jQuery-UI files
    that are actually present. Their location is generated by javadoc and
    JDK 23 and later no longer bundle jQuery, so the unconditional ln(1)
    calls failed the build on JDK 25.
  * SECURITY UPDATE: denial of service in the Erlang Port Mapper Daemon
    - debian/patches/CVE-2026-42792.patch: epmd: Improve slow-connection
      handling in erts/epmd/src/epmd_srv.c.
    - CVE-2026-42792
  * SECURITY UPDATE: heap corruption via crafted external term format data
    - debian/patches/CVE-2026-55737.patch: erts: Fixes heap pointer corruption
      via signed/unsigned mismatch in erts/emulator/beam/external.c.
    - CVE-2026-55737
  * SECURITY UPDATE: denial of service via crafted external term format data
    - debian/patches/CVE-2026-54890.patch: erts: Fix crash on decoding invalid
      ETF terms in erts/emulator/beam/external.c,
      erts/emulator/test/binary_SUITE.erl.
    - CVE-2026-54890
  * SECURITY UPDATE: buffer overflow via crafted packet length
    - debian/patches/CVE-2026-75538.patch: Avoid signed int overflows in
      erts/emulator/beam/packet_parser.c,
      erts/emulator/drivers/common/inet_drv.c.
    - CVE-2026-75538
  * SECURITY UPDATE: buffer overflow in the megaco flex scanner
    - debian/patches/CVE-2026-59250.patch: megaco: fix sprintf buffer overflow
      in flex scanner in lib/megaco/src/flex/megaco_flex_scanner_drv.flex.src.
    - CVE-2026-59250
  * SECURITY UPDATE: TLS clients accepted cipher suites they did not offer
    - debian/patches/CVE-2026-55953.patch: ssl: Add pre TLS-1.3 client cipher
      suite check in lib/ssl/src/ssl_handshake.erl.
    - CVE-2026-55953
  * SECURITY UPDATE: denial of service via crafted certificate chains
    - debian/patches/CVE-2026-58227.patch: ssl: Use digraph to ensure robust
      cert chain building. in lib/ssl/src/ssl_certificate.erl,
      lib/ssl/test/ssl_cert_SUITE.erl.
    - CVE-2026-58227
  * SECURITY UPDATE: denial of service via crafted certificate policies
    - debian/patches/CVE-2026-59251.patch: public_key: Cap policy tree growth to
      prevent DoS in lib/public_key/include/public_key.hrl,
      lib/public_key/src/pubkey_cert.erl,
      lib/public_key/src/pubkey_policy_tree.erl,
      lib/public_key/src/public_key.erl,
      lib/public_key/test/pubkey_policy_tree_SUITE.erl,
      lib/ssl/src/ssl_handshake.erl.
    - CVE-2026-59251
  * SECURITY UPDATE: HTTP request smuggling via conflicting framing headers
    - debian/patches/CVE-2026-73812-pre1.patch: Prevent httpd from parsing HTTP
      requests when multiple Content-Length headers are present in
      lib/inets/src/http_server/httpd_request.erl,
      lib/inets/src/http_server/httpd_request_handler.erl,
      lib/inets/test/httpd_SUITE.erl.
    - debian/patches/CVE-2026-73812.patch: inets: Reject requests with both
      Transfer-Encoding and Content-Length in
      lib/inets/src/http_server/httpd_internal.hrl,
      lib/inets/src/http_server/httpd_request.erl,
      lib/inets/test/http_test_lib.erl, lib/inets/test/httpc_SUITE.erl.
    - CVE-2026-23941
    - CVE-2026-73812
  * SECURITY UPDATE: denial of service via malformed chunk sizes
    - debian/patches/CVE-2026-69664.patch: inets: Fix rejection of invalid chunk
      sizes in lib/inets/src/http_server/httpd_request_handler.erl,
      lib/inets/test/httpd_SUITE.erl.
    - CVE-2026-69664
  * SECURITY UPDATE: denial of service via unbounded chunked request bodies
    - debian/patches/CVE-2026-74835.patch: inets: Fix max_body_size to apply to
      chunks as we receive them in lib/inets/src/http_lib/http_chunk.erl,
      lib/inets/src/http_server/httpd_request_handler.erl,
      lib/inets/test/http_format_SUITE.erl,
      lib/inets/test/httpd_basic_SUITE.erl.
    - debian/patches/CVE-2026-74835-2.patch: Fix
      httpd_basic_SUITE:chunked_body_size_unbounded/1 testcase for
      patch-base-27 in lib/inets/test/httpd_basic_SUITE.erl.
    - CVE-2026-74835
  * SECURITY UPDATE: authentication bypass via path equivalence / authentication bypass via inconsistent case handling
    - debian/patches/CVE-2026-66835_73270.patch: inets: Canonicalize request
      path before mod_auth directory check in
      lib/inets/src/http_server/httpd_request.erl,
      lib/inets/src/http_server/httpd_util.erl,
      lib/inets/src/http_server/mod_alias.erl,
      lib/inets/src/http_server/mod_auth.erl.
    - CVE-2026-66835
    - CVE-2026-73270
  * SECURITY UPDATE: denial of service via unlimited simultaneous connections
    - debian/patches/CVE-2026-70399.patch: inets: Fix default max_clients in
      lib/inets/src/http_lib/http_internal.hrl,
      lib/inets/src/http_server/httpd_manager.erl,
      lib/inets/test/httpd_SUITE.erl, lib/inets/test/httpd_basic_SUITE.erl.
    - CVE-2026-70399
  * SECURITY UPDATE: HTTP request smuggling via header continuation lines
    - debian/patches/CVE-2026-66357.patch: inets: Reject obs-fold header
      continuation in httpd (RFC 9112) in
      lib/inets/src/http_server/httpd_request.erl,
      lib/inets/test/httpd_SUITE.erl.
    - CVE-2026-66357
  * SECURITY UPDATE: HTTP request smuggling via malformed header names
    - debian/patches/CVE-2026-73276.patch: inets: Reject headers with whitespace
      before colon in httpd in lib/inets/src/http_lib/http_request.erl,
      lib/inets/src/http_server/httpd_request.erl,
      lib/inets/test/httpd_SUITE.erl.
    - debian/patches/CVE-2026-73276-2.patch: httpd: add error handling for
      headers with whitespace before colon in
      lib/inets/src/http_lib/http_request.erl,
      lib/inets/src/http_server/httpd_internal.hrl,
      lib/inets/src/http_server/httpd_request.erl.
    - CVE-2026-73276
  * SECURITY UPDATE: authentication bypass via inconsistent case handling
    - debian/patches/CVE-2026-73270-2.patch: inets: Add caseless matching to
      mod_security directory lookup in lib/inets/doc/guides/h

CVE-2026-42792 Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to permanently terminat
CVE-2026-55737 Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can supply a crafted Erlang exter
CVE-2026-54890 Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modules) allows Forced Integer Ov
CVE-2026-75538 An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an incorrect packet
CVE-2026-59250 Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and p
CVE-2026-55953 The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the su
CVE-2026-58227 The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS or DTLS handshake. In ssl
CVE-2026-59251 Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial
CVE-2026-73812 httpd function check_header/3 rejects duplicate Content-Length (per CVE-2026-23941) but never checks for the TE+CL co-presence that RFC 9112 §6.3 ide
CVE-2026-23941 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in Erlang OTP (inets httpd module) allows HTTP Request Smugglin
CVE-2026-69664 Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denia
CVE-2026-74835 The inets application HTTP server httpd fails to enforce a configured body-size limit on chunked request. This issue affects OTP from OTP 17.0 befor
CVE-2026-66835 Path Equivalence vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_auth protected directory
CVE-2026-73270 Improper Handling of Case Sensitivity vulnerability in Erlang/OTP inets httpd allows a remote unauthenticated attacker to read files inside a mod_aut
CVE-2026-70399 Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denia
CVE-2026-66357 httpd has never implemented obs-fold (RFC 2616 §2.2 / RFC 7230 §3.2.4 header continuation lines). Every CRLF followed by a non-CRLF octet uncondition
CVE-2026-73276 Gracefulness code ignored cases that should be rejected, resulting in possible HTTP Request Smuggling opportunities. This issue affects OTP from OTP
CVE-2026-71380 Missing Release of Resource after Effective Lifetime vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denia
CVE-2026-55951 The Erlang/OTP httpc HTTP client does not enforce a limit on the total size of response headers received from a server. The max_header_size option de



About   -   Send Feedback to @ubuntu_updates