[ubuntu/resolute-security] erlang 1:27.3.4.6+dfsg-1ubuntu0.1 (Accepted)

John Breton john.breton at canonical.com
Mon Sep 28 00:19:17 UTC 2026


erlang (1:27.3.4.6+dfsg-1ubuntu0.1) resolute-security; urgency=medium

  * debian/rules: only replace the javadoc-bundled jQuery/jQuery-UI files
    that are actually present.  Their location is generated by javadoc and
    JDK 23 and later no longer bundle jQuery, so the unconditional ln(1)
    calls failed the build on JDK 25.
  * SECURITY UPDATE: denial of service in the Erlang Port Mapper Daemon
    - debian/patches/CVE-2026-42792.patch: epmd: Improve slow-connection
      handling in erts/epmd/src/epmd_srv.c.
    - CVE-2026-42792
  * SECURITY UPDATE: heap corruption via crafted external term format data
    - debian/patches/CVE-2026-55737.patch: erts: Fixes heap pointer corruption
      via signed/unsigned mismatch in erts/emulator/beam/external.c.
    - CVE-2026-55737
  * SECURITY UPDATE: denial of service via crafted external term format data
    - debian/patches/CVE-2026-54890.patch: erts: Fix crash on decoding invalid
      ETF terms in erts/emulator/beam/external.c,
      erts/emulator/test/binary_SUITE.erl.
    - CVE-2026-54890
  * SECURITY UPDATE: buffer overflow via crafted packet length
    - debian/patches/CVE-2026-75538.patch: Avoid signed int overflows in
      erts/emulator/beam/packet_parser.c,
      erts/emulator/drivers/common/inet_drv.c.
    - CVE-2026-75538
  * SECURITY UPDATE: buffer overflow in the megaco flex scanner
    - debian/patches/CVE-2026-59250.patch: megaco: fix sprintf buffer overflow
      in flex scanner in lib/megaco/src/flex/megaco_flex_scanner_drv.flex.src.
    - CVE-2026-59250
  * SECURITY UPDATE: TLS clients accepted cipher suites they did not offer
    - debian/patches/CVE-2026-55953.patch: ssl: Add pre TLS-1.3 client cipher
      suite check in lib/ssl/src/ssl_handshake.erl.
    - CVE-2026-55953
  * SECURITY UPDATE: denial of service via crafted certificate chains
    - debian/patches/CVE-2026-58227.patch: ssl: Use digraph to ensure robust
      cert chain building. in lib/ssl/src/ssl_certificate.erl,
      lib/ssl/test/ssl_cert_SUITE.erl.
    - CVE-2026-58227
  * SECURITY UPDATE: denial of service via crafted certificate policies
    - debian/patches/CVE-2026-59251.patch: public_key: Cap policy tree growth to
      prevent DoS in lib/public_key/include/public_key.hrl,
      lib/public_key/src/pubkey_cert.erl,
      lib/public_key/src/pubkey_policy_tree.erl,
      lib/public_key/src/public_key.erl,
      lib/public_key/test/pubkey_policy_tree_SUITE.erl,
      lib/ssl/src/ssl_handshake.erl.
    - CVE-2026-59251
  * SECURITY UPDATE: HTTP request smuggling via conflicting framing headers
    - debian/patches/CVE-2026-73812-pre1.patch: Prevent httpd from parsing HTTP
      requests when multiple Content-Length headers are present in
      lib/inets/src/http_server/httpd_request.erl,
      lib/inets/src/http_server/httpd_request_handler.erl,
      lib/inets/test/httpd_SUITE.erl.
    - debian/patches/CVE-2026-73812.patch: inets: Reject requests with both
      Transfer-Encoding and Content-Length in
      lib/inets/src/http_server/httpd_internal.hrl,
      lib/inets/src/http_server/httpd_request.erl,
      lib/inets/test/http_test_lib.erl, lib/inets/test/httpc_SUITE.erl.
    - CVE-2026-23941
    - CVE-2026-73812
  * SECURITY UPDATE: denial of service via malformed chunk sizes
    - debian/patches/CVE-2026-69664.patch: inets: Fix rejection of invalid chunk
      sizes in lib/inets/src/http_server/httpd_request_handler.erl,
      lib/inets/test/httpd_SUITE.erl.
    - CVE-2026-69664
  * SECURITY UPDATE: denial of service via unbounded chunked request bodies
    - debian/patches/CVE-2026-74835.patch: inets: Fix max_body_size to apply to
      chunks as we receive them in lib/inets/src/http_lib/http_chunk.erl,
      lib/inets/src/http_server/httpd_request_handler.erl,
      lib/inets/test/http_format_SUITE.erl,
      lib/inets/test/httpd_basic_SUITE.erl.
    - debian/patches/CVE-2026-74835-2.patch: Fix
      httpd_basic_SUITE:chunked_body_size_unbounded/1 testcase for
      patch-base-27 in lib/inets/test/httpd_basic_SUITE.erl.
    - CVE-2026-74835
  * SECURITY UPDATE: authentication bypass via path equivalence / authentication bypass via inconsistent case handling
    - debian/patches/CVE-2026-66835_73270.patch: inets: Canonicalize request
      path before mod_auth directory check in
      lib/inets/src/http_server/httpd_request.erl,
      lib/inets/src/http_server/httpd_util.erl,
      lib/inets/src/http_server/mod_alias.erl,
      lib/inets/src/http_server/mod_auth.erl.
    - CVE-2026-66835
    - CVE-2026-73270
  * SECURITY UPDATE: denial of service via unlimited simultaneous connections
    - debian/patches/CVE-2026-70399.patch: inets: Fix default max_clients in
      lib/inets/src/http_lib/http_internal.hrl,
      lib/inets/src/http_server/httpd_manager.erl,
      lib/inets/test/httpd_SUITE.erl, lib/inets/test/httpd_basic_SUITE.erl.
    - CVE-2026-70399
  * SECURITY UPDATE: HTTP request smuggling via header continuation lines
    - debian/patches/CVE-2026-66357.patch: inets: Reject obs-fold header
      continuation in httpd (RFC 9112) in
      lib/inets/src/http_server/httpd_request.erl,
      lib/inets/test/httpd_SUITE.erl.
    - CVE-2026-66357
  * SECURITY UPDATE: HTTP request smuggling via malformed header names
    - debian/patches/CVE-2026-73276.patch: inets: Reject headers with whitespace
      before colon in httpd in lib/inets/src/http_lib/http_request.erl,
      lib/inets/src/http_server/httpd_request.erl,
      lib/inets/test/httpd_SUITE.erl.
    - debian/patches/CVE-2026-73276-2.patch: httpd: add error handling for
      headers with whitespace before colon in
      lib/inets/src/http_lib/http_request.erl,
      lib/inets/src/http_server/httpd_internal.hrl,
      lib/inets/src/http_server/httpd_request.erl.
    - CVE-2026-73276
  * SECURITY UPDATE: authentication bypass via inconsistent case handling
    - debian/patches/CVE-2026-73270-2.patch: inets: Add caseless matching to
      mod_security directory lookup in lib/inets/doc/guides/http_server.md,
      lib/inets/src/http_server/httpd_util.erl,
      lib/inets/src/http_server/mod_security.erl.
    - CVE-2026-73270
  * SECURITY UPDATE: denial of service via incomplete request bodies
    - debian/patches/CVE-2026-71380-pre1.patch: inets: Adjust keep_alive_timeout
      effective measurement in httpd in
      lib/inets/src/http_server/httpd_conf.erl,
      lib/inets/src/http_server/httpd_request_handler.erl,
      lib/inets/test/httpd_SUITE.erl.
    - debian/patches/CVE-2026-71380-pre2.patch: inets: Add httpd option
      max_body_read_timeout in lib/inets/src/http_lib/http_internal.hrl,
      lib/inets/src/http_server/httpd.erl,
      lib/inets/src/http_server/httpd_conf.erl,
      lib/inets/src/http_server/httpd_request_handler.erl.
    - debian/patches/CVE-2026-71380-pre3.patch: inets: Send 408 when we hit
      min_bytes_per_second floor in
      lib/inets/src/http_server/httpd_request_handler.erl.
    - debian/patches/CVE-2026-71380.patch: inets: rename max_body_read_timeout
      option to request_timeout in lib/inets/src/http_lib/http_internal.hrl,
      lib/inets/src/http_server/httpd.erl,
      lib/inets/src/http_server/httpd_conf.erl,
      lib/inets/src/http_server/httpd_request_handler.erl.
    - debian/patches/CVE-2026-71380-2.patch: Fix dialyzer errors in
      httpd_request_handler in
      lib/inets/src/http_server/httpd_request_handler.erl.
    - CVE-2026-71380
  * SECURITY UPDATE: denial of service via unbounded HTTP response headers
    - debian/patches/CVE-2026-55951.patch: inets,stdlib,eldap: Bound integer
      parsing to mitigate DoS in lib/eldap/src/eldap.erl,
      lib/inets/src/http_client/httpc.erl,
      lib/inets/src/http_client/httpc_handler.erl,
      lib/inets/src/http_client/httpc_response.erl,
      lib/inets/src/http_lib/http_response.erl, lib/inets/test/httpc_SUITE.erl,
      lib/snmp/src/misc/snmp_pdus.erl, lib/stdlib/src/uri_string.erl.
    - CVE-2026-55951

Date: 2026-09-24 11:08:48.058809+00:00
Changed-By: John Breton <john.breton at canonical.com>
https://launchpad.net/ubuntu/+source/erlang/1:27.3.4.6+dfsg-1ubuntu0.1
-------------- next part --------------
Sorry, changesfile not available.


More information about the Resolute-changes mailing list