rpm package
opensuse/erlang&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/erlang&distro=openSUSE%20Tumbleweed
Vulnerabilities (30)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-59251 | Hig | 7.5 | < 28.5.0.4-1.1 | 28.5.0.4-1.1 | Jul 27, 2026 | Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial of service by sending a crafted X.509 certificate chain during the TLS handshake. During RFC 5280 policy processing in public_key: | |
| CVE-2026-59250 | Hig | — | < 28.5.0.4-1.1 | 28.5.0.4-1.1 | Jul 27, 2026 | Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and potentially achieve remote code execution or a denial-of-service crash) by sending a single text-encoded H.248/Megaco message contai | |
| CVE-2026-58227 | Hig | 7.5 | < 28.5.0.4-1.1 | 28.5.0.4-1.1 | Jul 27, 2026 | The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS or DTLS handshake. In ssl_certificate:handle_incomplete_chain/5, the received chain is passed to ssl_certificate:build_certificate_chain/5, which walks issu | |
| CVE-2026-55953 | Hig | 7.4 | < 28.5.0.4-1.1 | 28.5.0.4-1.1 | Jul 27, 2026 | The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello. The client-side tls_handshake:hello/5 handler validates the negotiated protocol version | |
| CVE-2026-55737 | Hig | 7.5 | < 28.5.0.4-1.1 | 28.5.0.4-1.1 | Jul 27, 2026 | Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can supply a crafted Erlang external term format (ETF) binary to binary_to_term/1 to corrupt the BEAM heap pointer and crash the virtual machine. When decoding a L | |
| CVE-2026-54890 | Hig | 7.5 | < 28.5.0.4-1.1 | 28.5.0.4-1.1 | Jul 27, 2026 | Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modules) allows Forced Integer Overflow, Excessive Allocation. This vulnerability is associated with program files erts/emulator/beam/external.c, emulator/beam/exte | |
| CVE-2026-47078 | Med | — | < 28.5.0.4-1.1 | 28.5.0.4-1.1 | Jul 27, 2026 | Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module) allows writing files outside the intended extraction directory via a crafted zip archive. zip:unzip/1,2 and zip:extract/1,2 validate entry paths using zip:check_dir_level/2, which tracks directory depth as a | |
| CVE-2026-42792 | Hig | 7.5 | < 28.5.0.4-1.1 | 28.5.0.4-1.1 | Jul 27, 2026 | Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to permanently terminate the Erlang Port Mapper Daemon (epmd) via connection slot exhaustion. The do_accept function in erts/epmd/src/epmd_srv.c calls ep | |
| CVE-2026-55952 | Hig | 7.5 | < 28.5.0.4-1.1 | 28.5.0.4-1.1 | Jul 2, 2026 | The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientHello pre-shared key extension have equal length before passing them to the session ticket handler. In tls_handshake_1_3:handle_pre_shared_key/3, an OfferedPreSh | |
| CVE-2026-55950 | Med | 5.9 | < 28.5.0.4-1.1 | 28.5.0.4-1.1 | Jul 2, 2026 | Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an unauthenticated remote attacker to crash all active DTLS sessions on a listener. A DTLS server listener uses a single shared dtls_packet_demux gen_server proces | |
| CVE-2026-54891 | Low | 3.7 | < 28.5.0.4-1.1 | 28.5.0.4-1.1 | Jul 2, 2026 | Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Erlang/OTP ssl (tls_gen_connection module) allows a network-positioned attacker to inject unauthenticated plaintext that the TLS client application later treats as authentica | |
| CVE-2026-54887 | Med | 4.8 | < 28.5.0.4-1.1 | 28.5.0.4-1.1 | Jul 2, 2026 | Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl (DTLS server) allows predictable DTLS cookie computation during the startup window, enabling source address verification bypass. On DTLS server startup, dtls_server_connection:initial_hello/3 initializes previous_c | |
| CVE-2026-54886 | Med | 4.3 | < 28.5.0.4-1.1 | 28.5.0.4-1.1 | Jul 2, 2026 | Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to render an SFTP channel permanently unresponsive. The handle_data/4 function in ssh_sftpd contains a catch-all clause that accepts channe | |
| CVE-2026-53422 | Med | 4.3 | < 28.5.0.4-1.1 | 28.5.0.4-1.1 | Jul 2, 2026 | Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to enumerate the existence of files and directories outside the configured root directory. The SSH_FXP_REALPATH handler in ssh_sftpd calls relate_file_name/3 with | |
| CVE-2026-49760 | Med | 5.5 | < 28.5.0.4-1.1 | 28.5.0.4-1.1 | Jun 10, 2026 | Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow. This vulnerability is associated with program file lib/erl_interface/src/misc/ei_printterm.c and program routine ei_s_print_term. The C function ei_s_print_term uses an i | |
| CVE-2026-49759 | Hig | 8.2 | < 28.5.0.4-1.1 | 28.5.0.4-1.1 | Jun 10, 2026 | Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk. The sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks a | |
| CVE-2026-48860 | Med | 6.5 | < 28.5.0.4-1.1 | 28.5.0.4-1.1 | Jun 10, 2026 | Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-over-TLS LAN allowlist. The inet_tls_dist:check_ip/1 function, which enforces a LAN allowlist for Erlang distribution over TLS, call | |
| CVE-2026-48858 | Med | 6.5 | < 28.5.0.4-1.1 | 28.5.0.4-1.1 | Jun 10, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and SSRF via an unvalidated PASV response IP address. The ftp_internal:handle_ctrl_result/2 PASV handler (mode=passive, ipfamily=inet, ftp_extension=false) extracts | |
| CVE-2026-48856 | Med | 6.5 | < 28.5.0.4-1.1 | 28.5.0.4-1.1 | Jun 10, 2026 | Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data. The httpc client forwards the Authorization and Proxy-Authorization request headers to redirect targets without checking whether the redirect crosses an ori | |
| CVE-2026-48855 | Med | 6.5 | < 28.5.0.4-1.1 | 28.5.0.4-1.1 | Jun 10, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery. The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client without calling chroot_filename/2 to strip the ba |
- affected < 28.5.0.4-1.1fixed 28.5.0.4-1.1
Allocation of resources without limits in Erlang/OTP public_key certificate path validation allows a remote unauthenticated attacker to cause denial of service by sending a crafted X.509 certificate chain during the TLS handshake. During RFC 5280 policy processing in public_key:
- affected < 28.5.0.4-1.1fixed 28.5.0.4-1.1
Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and potentially achieve remote code execution or a denial-of-service crash) by sending a single text-encoded H.248/Megaco message contai
- affected < 28.5.0.4-1.1fixed 28.5.0.4-1.1
The Erlang/OTP ssl application does not detect cycles when reconstructing an incomplete peer certificate chain during a TLS or DTLS handshake. In ssl_certificate:handle_incomplete_chain/5, the received chain is passed to ssl_certificate:build_certificate_chain/5, which walks issu
- affected < 28.5.0.4-1.1fixed 28.5.0.4-1.1
The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not verify that the cipher suite selected by the server in ServerHello was among the suites offered by the client in ClientHello. The client-side tls_handshake:hello/5 handler validates the negotiated protocol version
- affected < 28.5.0.4-1.1fixed 28.5.0.4-1.1
Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can supply a crafted Erlang external term format (ETF) binary to binary_to_term/1 to corrupt the BEAM heap pointer and crash the virtual machine. When decoding a L
- affected < 28.5.0.4-1.1fixed 28.5.0.4-1.1
Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erlang/otp (erts modules), erlang otp erts (erts modules) allows Forced Integer Overflow, Excessive Allocation. This vulnerability is associated with program files erts/emulator/beam/external.c, emulator/beam/exte
- affected < 28.5.0.4-1.1fixed 28.5.0.4-1.1
Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module) allows writing files outside the intended extraction directory via a crafted zip archive. zip:unzip/1,2 and zip:extract/1,2 validate entry paths using zip:check_dir_level/2, which tracks directory depth as a
- affected < 28.5.0.4-1.1fixed 28.5.0.4-1.1
Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to permanently terminate the Erlang Port Mapper Daemon (epmd) via connection slot exhaustion. The do_accept function in erts/epmd/src/epmd_srv.c calls ep
- affected < 28.5.0.4-1.1fixed 28.5.0.4-1.1
The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientHello pre-shared key extension have equal length before passing them to the session ticket handler. In tls_handshake_1_3:handle_pre_shared_key/3, an OfferedPreSh
- affected < 28.5.0.4-1.1fixed 28.5.0.4-1.1
Time-of-check Time-of-use (TOCTOU) race condition vulnerability in Erlang/OTP ssl (dtls_packet_demux module) allows an unauthenticated remote attacker to crash all active DTLS sessions on a listener. A DTLS server listener uses a single shared dtls_packet_demux gen_server proces
- affected < 28.5.0.4-1.1fixed 28.5.0.4-1.1
Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Erlang/OTP ssl (tls_gen_connection module) allows a network-positioned attacker to inject unauthenticated plaintext that the TLS client application later treats as authentica
- affected < 28.5.0.4-1.1fixed 28.5.0.4-1.1
Use of Default Cryptographic Key vulnerability in Erlang/OTP ssl (DTLS server) allows predictable DTLS cookie computation during the startup window, enabling source address verification bypass. On DTLS server startup, dtls_server_connection:initial_hello/3 initializes previous_c
- affected < 28.5.0.4-1.1fixed 28.5.0.4-1.1
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to render an SFTP channel permanently unresponsive. The handle_data/4 function in ssh_sftpd contains a catch-all clause that accepts channe
- affected < 28.5.0.4-1.1fixed 28.5.0.4-1.1
Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to enumerate the existence of files and directories outside the configured root directory. The SSH_FXP_REALPATH handler in ssh_sftpd calls relate_file_name/3 with
- affected < 28.5.0.4-1.1fixed 28.5.0.4-1.1
Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow. This vulnerability is associated with program file lib/erl_interface/src/misc/ei_printterm.c and program routine ei_s_print_term. The C function ei_s_print_term uses an i
- affected < 28.5.0.4-1.1fixed 28.5.0.4-1.1
Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk. The sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks a
- affected < 28.5.0.4-1.1fixed 28.5.0.4-1.1
Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated bypass of the distribution-over-TLS LAN allowlist. The inet_tls_dist:check_ip/1 function, which enforces a LAN allowlist for Erlang distribution over TLS, call
- affected < 28.5.0.4-1.1fixed 28.5.0.4-1.1
Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and SSRF via an unvalidated PASV response IP address. The ftp_internal:handle_ctrl_result/2 PASV handler (mode=passive, ipfamily=inet, ftp_extension=false) extracts
- affected < 28.5.0.4-1.1fixed 28.5.0.4-1.1
Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Data. The httpc client forwards the Authorization and Proxy-Authorization request headers to redirect targets without checking whether the redirect crosses an ori
- affected < 28.5.0.4-1.1fixed 28.5.0.4-1.1
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows File Discovery. The SSH_FXP_READLINK handler in ssh_sftpd sends the raw result of file:read_link/2 to the client without calling chroot_filename/2 to strip the ba
Page 1 of 2