CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

DSA-6464-1 erlang - security update

unknownCVE-2026-28808CVE-2026-28810CVE-2026-32144CVE-2026-32147CVE-2026-42789CVE-2026-42790
Multiple vulnerabilities were discovered in Erlang/OTP, a concurrent, real-time, distributed functional language, which may result in denial of service, information disclosure, authentication and certificate validation bypass, or the execution of arbitrary code. These vulnerbilities affect a wide range of components: TLS and certificate validation (ssl, public_key), SSH (ssh), network clients and servers (inets, ftp, epmd, kernel), runtime and libraries (erts, erl_interface, stdlib, megaco). Several of these fixes tighten checks that were previously too permissive, and can cause configurations that worked before to stop working. The most likely to be noticed are: - TLS clients using verify_peer, which is the default, now reject certificates that carry no subjectAltName extension; the customize_hostname_check option does not restore the old behaviour. - Erlang distribution over TLS with the kernel 'check_ip' option now enforces the check that was previously a no-op, so clusters whose nodes are not on the same subnet lose distribution connectivity until the option is unset. - TLS clients that request OCSP stapling now fail the handshake when the server provides no stapled response. - Clients using TLS 1.2 or earlier now abort the handshake if the server sends an ALPN extension that the client did not advertise. - DNS queries made through inet_res now use randomised source ports https://security-tracker.debian.org/tracker/DSA-6464-1

CSIRTS triage

What
Multiple vulnerabilities across TLS, SSH, network clients, and runtime components allow denial of service, information disclosure, authentication bypass, and arbitrary code execution.
Who is affected
Erlang/OTP deployments using affected versions; TLS clients and SSH components are most impacted.
Urgency
High; vulnerabilities span critical subsystems; some fixes restrict previous permissive behavior and may affect production configurations.
Action
Upgrade Erlang/OTP to the patched version and review TLS certificate validation and distribution configurations for compatibility.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Erlang/OTP

Get an email when a new Erlang/OTP advisory drops — max one per day, one-click unsubscribe.

Details

Source
Debian Security Advisories (INTL · vendor-psirt · site)
Severity
unknown
Published
2026-08-25
Exploitation
Not in CISA KEV at last sync

Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00375.html

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-28808coverage & exploitation statusNVD · CVE.org
CVE-2026-28810coverage & exploitation statusNVD · CVE.org
CVE-2026-32144coverage & exploitation statusNVD · CVE.org
CVE-2026-32147coverage & exploitation statusNVD · CVE.org
CVE-2026-42789coverage & exploitation statusNVD · CVE.org
CVE-2026-42790coverage & exploitation statusNVD · CVE.org
CVE-2026-42791coverage & exploitation statusNVD · CVE.org
CVE-2026-42792coverage & exploitation statusNVD · CVE.org
CVE-2026-47078coverage & exploitation statusNVD · CVE.org
CVE-2026-48855coverage & exploitation statusNVD · CVE.org
CVE-2026-48856coverage & exploitation statusNVD · CVE.org
CVE-2026-48858coverage & exploitation statusNVD · CVE.org
CVE-2026-48860coverage & exploitation statusNVD · CVE.org
CVE-2026-49759coverage & exploitation statusNVD · CVE.org
CVE-2026-49760coverage & exploitation statusNVD · CVE.org
CVE-2026-53422coverage & exploitation statusNVD · CVE.org
CVE-2026-54886coverage & exploitation statusNVD · CVE.org
CVE-2026-54887coverage & exploitation statusNVD · CVE.org
CVE-2026-54890coverage & exploitation statusNVD · CVE.org
CVE-2026-54891coverage & exploitation statusNVD · CVE.org
CVE-2026-55737coverage & exploitation statusNVD · CVE.org
CVE-2026-55950coverage & exploitation statusNVD · CVE.org
CVE-2026-55952coverage & exploitation statusNVD · CVE.org
CVE-2026-55953coverage & exploitation statusNVD · CVE.org
CVE-2026-58227coverage & exploitation statusNVD · CVE.org
CVE-2026-59250coverage & exploitation statusNVD · CVE.org
CVE-2026-59251coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Debian Security Advisories