-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 22 Aug 2026 22:38:30 +0300 Source: erlang Architecture: source Version: 1:27.3.4.1+dfsg-1+deb13u3 Distribution: trixie-security Urgency: medium Maintainer: Debian Erlang Packagers <pkg-erlang-devel@lists.alioth.debian.org> Changed-By: Sergei Golovan <sgolovan@debian.org> Closes: 1139727 1139823 1141414 1142985 Changes: erlang (1:27.3.4.1+dfsg-1+deb13u3) trixie-security; urgency=medium . [ Aron Xu ] * Add a series of patches by upstream, which fix a set of vulnerabilities: - Fix CVE-2026-48855: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh application (ssh_sftpd module). - Fix CVE-2026-48856: Sensitive Data Exposure vulnerability in Erlang OTP inets application (httpc_response module). - Fix CVE-2026-48858: Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp application (ftp_internal module). - Fix CVE-2026-48859: Observable Timing Discrepancy vulnerability in Erlang/OTP ssh application (ssh_auth, ssh_options modules). - Fix CVE-2026-48860: Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl application (inet_tls_dist module). - Fix CVE-2026-49759: Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv). - Fix CVE-2026-49760: Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface). Closes: #1139727, #1139823. - Fix CVE-2026-53422: Observable Response Discrepancy vulnerability in Erlang OTP ssh application (ssh_sftpd module). - Fix CVE-2026-54886: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Erlang OTP ssh application (ssh_sftpd module). - Fix CVE-2026-54887: Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl application (DTLS server) - Fix CVE-2026-54891: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Erlang/OTP ssl application (tls_gen_connection module). - Fix CVE-2026-55950: Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl application (dtls_packet_demux module). - Fix CVE-2026-55952: The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientHello pre-shared key extension have equal length before passing them to the session ticket handler. Closes: #1141414. - Fix CVE-2026-42792: Improper Handling of Exceptional Conditions vulnerability in Erlang/OTP epmd daemon. - Fix CVE-2026-47078: Relative Path Traversal vulnerability in Erlang/OTP stdlib (zip module). - Fix CVE-2026-54890: Integer Underflow (Wrap or Wraparound) vulnerability in Erlang/OTP erts. - Fix CVE-2026-55737: Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang/OTP erts. - Fix CVE-2026-55953: The Erlang/OTP ssl TLS and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello. - Fix CVE-2026-58227: The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS or DTLS handshake. - Fix CVE-2026-59250: Buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory. - Fix CVE-2026-59251: Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial of service. Closes: #1142985. - Fix CVE-2026-28808: Incorrect Authorization vulnerability in Erlang/OTP (inets modules) allows unauthenticated access to CGI scripts. - Fix CVE-2026-28810: Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache Poisoning. - Fix CVE-2026-32144: Improper Certificate Validation vulnerability in Erlang/OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via missing signature verification. - Fix CVE-2026-32147: Vulnerability in the SFTP server where file attributes could be modified outside the configured root directory. - Fix CVE-2026-42789: Improper Following of a Certificate's Chain of Trust vulnerability in Erlang/OTP public_key application allows a non-CA certificate to be accepted as an intermediate issuer. - Fix CVE-2026-42790: Improper Certificate Validation vulnerability in Erlang/OTP public_key application allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification. - Fix CVE-2026-42791: Improper Certificate Validation vulnerability in Erlang/OTP public_key application allows forged OCSP responses signed with an expired responder certificate to be accepted as valid. Checksums-Sha1: 259dcf8b869635e210af9ca48e2f0a540b21b7ee 4945 erlang_27.3.4.1+dfsg-1+deb13u3.dsc c5e31111a88a6175bcdbb333ef2fdf172500a6ce 47613664 erlang_27.3.4.1+dfsg.orig.tar.xz db36da86edd129fe2d6663642038cb339ab684f6 150788 erlang_27.3.4.1+dfsg-1+deb13u3.debian.tar.xz c0ff0d2d9a02080791217c5bb413a646a910a015 32481 erlang_27.3.4.1+dfsg-1+deb13u3_amd64.buildinfo Checksums-Sha256: 698cabb961a0d38b31465cc35195f92085f5c569d5a4b53b3be9f7df110a9ff2 4945 erlang_27.3.4.1+dfsg-1+deb13u3.dsc 0834643ef1e17886d5e334a39527d8429bcf50613b86d59d4757466f32984b7e 47613664 erlang_27.3.4.1+dfsg.orig.tar.xz 3499b90f23dedc9df7634527f06862ab5f1acded5c4b22bf4eab23b2fbd68b7f 150788 erlang_27.3.4.1+dfsg-1+deb13u3.debian.tar.xz 5f87591f0413bc9e5e0df60004676ecbf9c908029801e5dfc76a838220f72cc2 32481 erlang_27.3.4.1+dfsg-1+deb13u3_amd64.buildinfo Files: 2dc1f345c534e281ca125c2256344238 4945 interpreters optional erlang_27.3.4.1+dfsg-1+deb13u3.dsc 8e316a9e63f5c4167ba34596b146ab35 47613664 interpreters optional erlang_27.3.4.1+dfsg.orig.tar.xz 309623097689889bcbd3483c8185737d 150788 interpreters optional erlang_27.3.4.1+dfsg-1+deb13u3.debian.tar.xz c1ed916a4d2174a62a417204273a68e0 32481 interpreters optional erlang_27.3.4.1+dfsg-1+deb13u3_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE/SYPsyDB+ShSnvc4Tyrk60tj54cFAmqLNboACgkQTyrk60tj 54cUyQ//QYEBb5KzGh0m3NsbPMfj9XH+fF9IpNpnxWVpKZkztHED958ZUZY9d/mB 49rovT0zfbxNc/ncYSqOBB0ooVD+ehEFX75hLPHMLUABjloOnlqtKjMZ8nT7aMAS 6Ce/hRIfozkHKJe6pZKXMMjx/KirO9dIhbD5JZu7nsvOgUr05doel+OkDKtO5Zj4 ArTWRubhHw2QQ5LOmrhONHRrnRklYl7Y9W/DjaUCkn13xqx44dj5DtOAzJeC8vSc T3eQXMjsznfZ3k/mCRl3Trdk/TtW6fY4fO+6J5LY/8drZT2meAl90SeVcPuexohj qA7yYoioXWNHF3HTYsvLy5GTNWS4OCLJcKB0GUYVHlbmuCShSgnu/NlKG31Hm6P/ JVM3JVJ7nDAeNXMAvwXDN2ux6rkuowJa1hSVxiWwstLYSo7YqIQFqz/ODn8/t+wh 5JH4gWxBWt1t5H1ZCFUNmiiIfYfXhxnosrs0iZKqMKJrVib2OeeXe6jtdVbXFIEn 8GQIEiyhIArQXld/r9mtfkEKytGQjPQSc0P5JBScZSL3XsD4K7cMeys8BD+KgN08 mhHMCGwgiDunquSDariY8vlataGISwPMq+i0EVIvXMrRA9fKJP50Mj+HxYTGTHq5 SAlzMg0NjzB1k1r50Dt+jbMy7c9PduC6R8kzdQgUm7TKqUBj8Ds= =tMMc -----END PGP SIGNATURE-----