-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 22 Aug 2026 22:38:30 +0300 Source: erlang Binary: erlang erlang-doc erlang-examples erlang-jinterface erlang-mode erlang-nox erlang-src erlang-x11 Architecture: all Version: 1:27.3.4.1+dfsg-1+deb13u3 Distribution: trixie-security Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-grnet-03) Changed-By: Sergei Golovan Description: erlang - Concurrent, real-time, distributed functional language erlang-doc - Erlang/OTP HTML documentation erlang-examples - Erlang/OTP application examples erlang-jinterface - Java communication tool to Erlang erlang-mode - Erlang major editing mode for Emacs erlang-nox - Erlang/OTP applications that don't require X Window System erlang-src - Erlang/OTP applications sources erlang-x11 - Erlang/OTP applications that require X Window System Closes: 1139727 1139823 1141414 1142985 Changes: erlang (1:27.3.4.1+dfsg-1+deb13u3) trixie-security; urgency=medium . [ Aron Xu ] * Add a series of patches by upstream, which fix a set of vulnerabilities: - Fix CVE-2026-48855: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh application (ssh_sftpd module). - Fix CVE-2026-48856: Sensitive Data Exposure vulnerability in Erlang OTP inets application (httpc_response module). - Fix CVE-2026-48858: Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp application (ftp_internal module). - Fix CVE-2026-48859: Observable Timing Discrepancy vulnerability in Erlang/OTP ssh application (ssh_auth, ssh_options modules). - Fix CVE-2026-48860: Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl application (inet_tls_dist module). - Fix CVE-2026-49759: Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv). - Fix CVE-2026-49760: Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface). Closes: #1139727, #1139823. - Fix CVE-2026-53422: Observable Response Discrepancy vulnerability in Erlang OTP ssh application (ssh_sftpd module). - Fix CVE-2026-54886: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Erlang OTP ssh application (ssh_sftpd module). - Fix CVE-2026-54887: Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl application (DTLS server) - Fix CVE-2026-54891: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Erlang/OTP ssl application (tls_gen_connection module). - Fix CVE-2026-55950: Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl application (dtls_packet_demux module). - Fix CVE-2026-55952: The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientHello pre-shared key extension have equal length before passing them to the session ticket handler. Closes: #1141414. - Fix CVE-2026-42792: Improper Handling of Exceptional Conditions vulnerability in Erlang/OTP epmd daemon. - Fix CVE-2026-47078: Relative Path Traversal vulnerability in Erlang/OTP stdlib (zip module). - Fix CVE-2026-54890: Integer Underflow (Wrap or Wraparound) vulnerability in Erlang/OTP erts. - Fix CVE-2026-55737: Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang/OTP erts. - Fix CVE-2026-55953: The Erlang/OTP ssl TLS and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello. - Fix CVE-2026-58227: The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS or DTLS handshake. - Fix CVE-2026-59250: Buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory. - Fix CVE-2026-59251: Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial of service. Closes: #1142985. - Fix CVE-2026-28808: Incorrect Authorization vulnerability in Erlang/OTP (inets modules) allows unauthenticated access to CGI scripts. - Fix CVE-2026-28810: Generation of Predictable Numbers or Identifiers vulnerability in Erlang/OTP kernel (inet_res, inet_db modules) allows DNS Cache Poisoning. - Fix CVE-2026-32144: Improper Certificate Validation vulnerability in Erlang/OTP public_key (pubkey_ocsp module) allows OCSP designated-responder authorization bypass via missing signature verification. - Fix CVE-2026-32147: Vulnerability in the SFTP server where file attributes could be modified outside the configured root directory. - Fix CVE-2026-42789: Improper Following of a Certificate's Chain of Trust vulnerability in Erlang/OTP public_key application allows a non-CA certificate to be accepted as an intermediate issuer. - Fix CVE-2026-42790: Improper Certificate Validation vulnerability in Erlang/OTP public_key application allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verification. - Fix CVE-2026-42791: Improper Certificate Validation vulnerability in Erlang/OTP public_key application allows forged OCSP responses signed with an expired responder certificate to be accepted as valid. Checksums-Sha1: 4a67063a91a99258309b54d13be7ff055e6410b8 16829404 erlang-doc_27.3.4.1+dfsg-1+deb13u3_all.deb 5c93f4bcc5dd6d4d16c35c8e9d413054a2ddc0b7 965076 erlang-examples_27.3.4.1+dfsg-1+deb13u3_all.deb 74b3f6837d7542225d8f2f362bb51c48b68b7c2f 115952 erlang-jinterface_27.3.4.1+dfsg-1+deb13u3_all.deb bceb1a6abb2b58275d85496c1ba88d5cc73b77fb 95692 erlang-mode_27.3.4.1+dfsg-1+deb13u3_all.deb e60debda3e0b432d8de0bb6ca74a0c8895301ee8 17276 erlang-nox_27.3.4.1+dfsg-1+deb13u3_all.deb 1fbd3de506aadc689654b30f9eafb1a6366733e8 6120068 erlang-src_27.3.4.1+dfsg-1+deb13u3_all.deb e9c134f05f052e348345b73d9e801401100f7271 17228 erlang-x11_27.3.4.1+dfsg-1+deb13u3_all.deb 7cc4718de73617eb05fc8cd3fb739ef1064aa70e 18884 erlang_27.3.4.1+dfsg-1+deb13u3_all-buildd.buildinfo 895c56e38cb753c6eeb077191f614a554225e699 17620 erlang_27.3.4.1+dfsg-1+deb13u3_all.deb Checksums-Sha256: bbb9c55f0b804a1e8e95194b0a5246904b698b09776eda91e73f24b8fb5d8609 16829404 erlang-doc_27.3.4.1+dfsg-1+deb13u3_all.deb 831ec10469688d281f3450082bd60c4ffc48dbe197327704f75119f4b39e3d3b 965076 erlang-examples_27.3.4.1+dfsg-1+deb13u3_all.deb 09f9f83be5a8f3972b65cae11f42bc15c8b6db21f6dc90035f6d8b135b2fe1ce 115952 erlang-jinterface_27.3.4.1+dfsg-1+deb13u3_all.deb c19401645b49dea822daa18d3fe27f76b767721453f8a27e4ef9ea7ac1620154 95692 erlang-mode_27.3.4.1+dfsg-1+deb13u3_all.deb 9fd086336cce423f11b40f0ecfc4797090ae773adb97b5a985cbca5b88773e97 17276 erlang-nox_27.3.4.1+dfsg-1+deb13u3_all.deb 2d2a08225e0580f6ab8bc29d76e2f57e53d3e5197e4d8ccef03041fc91f08b92 6120068 erlang-src_27.3.4.1+dfsg-1+deb13u3_all.deb 690db26479fa11907e6024e128ce8b5d5c8e59c02c613eb713ab137c5f20efa9 17228 erlang-x11_27.3.4.1+dfsg-1+deb13u3_all.deb c3d77f96bfb2e79a84c119a3d1bcfd53cd88fe430503b45c85949f6ef92a0c49 18884 erlang_27.3.4.1+dfsg-1+deb13u3_all-buildd.buildinfo 02a1423d35f48371edc04fdb72a75f0ddbac03e3387057f77fa313ba8fa48ce5 17620 erlang_27.3.4.1+dfsg-1+deb13u3_all.deb Files: 8007e29b6e2d1f1d25b7376464a7e0e0 16829404 doc optional erlang-doc_27.3.4.1+dfsg-1+deb13u3_all.deb 490112dcfa378e761b13fe7b183f9565 965076 interpreters optional erlang-examples_27.3.4.1+dfsg-1+deb13u3_all.deb d949d2ed7107aad16a21b9eab2ae64bf 115952 interpreters optional erlang-jinterface_27.3.4.1+dfsg-1+deb13u3_all.deb d087c7875fcb66e63c30423e3caff1de 95692 interpreters optional erlang-mode_27.3.4.1+dfsg-1+deb13u3_all.deb 42b76f4c10fe3b2ee3029158f5f7a5fe 17276 interpreters optional erlang-nox_27.3.4.1+dfsg-1+deb13u3_all.deb 0e0efdf9ce321647691e08b1fc93adcf 6120068 interpreters optional erlang-src_27.3.4.1+dfsg-1+deb13u3_all.deb 04ab6c124606e79c4cb1af0c3cb7e352 17228 interpreters optional erlang-x11_27.3.4.1+dfsg-1+deb13u3_all.deb 7ff5c34210efffc0ea3315035f1af9d3 18884 interpreters optional erlang_27.3.4.1+dfsg-1+deb13u3_all-buildd.buildinfo 97229e268c2e59ded55b443e029c2a21 17620 interpreters optional erlang_27.3.4.1+dfsg-1+deb13u3_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE5ZI1lXv5WjhHIVjsN8Ugyu9dQiQFAmqLP/IACgkQN8Ugyu9d QiQy+g/5AZ4KOLIw7D0+jmQ1do+wU5Hu9pKVBUFrUaOxOnYFM3RzTe7BIL1+Z7L5 V2Wg/Pvstlrnc+xajo5d3oy8eKqIhnQpMZmQhtZGivyWR5UF0AZEsUB7ll6Yw6b6 q03G3emkfFQr2kbMybSt07enWyzzAueTEkT1yzQVYDJoN/yw498yZ1bH6RcAGWvE TZhlqYuGM99g9Jy0qr/gsKwDJ++4JbH9x8/73uvzeIxp0GtWuAxrb8zYfaNXmI/O mrZg7UUUdL22C9Upt59XwPoC5NIj63w9ttcdoK5CMfWmccNqRKJOpUCTgra4LpVF KonWGQSwyKfcjiCFzQ/TdOKs6/0x1cjBbHaZq0qjEBmDlL3Cem3dsP2x41iT6rTD yqCTtMto2040dg1907W57hJsV3yXQk89yCo8TVVDfNnkgJy+RZzwaFrrIeTRR7aF nO+M2BC7gRMhYJPRQ9jeb3Vt+VNVS5IfRrUMo0jj/lizYXa0UfWoKiDv+4GMEs1W jY3WJOKfTqW1KiQnp0kXaeUmTJhf7Jgs8hnQtx8n2/Fqq/S1/jLVIsHMFfQdzwgA 1pMwIww5YlITb4eprHOo/mzJ44BNhKX/G5Fm7VF3z2hHDELPdXzZhy+5iJEsUqgH CLEw0r1hGWiA3YmF5wbLIzlwSv0GM+Yr/XUcQvHCSakZq6CbJNU= =z6Qp -----END PGP SIGNATURE-----