DSA-6464-1 erlang - security update
Multiple vulnerabilities were discovered in Erlang/OTP, a concurrent, real-time, distributed functional language, which may result in denial of service, information disclosure, authentication and certificate validation bypass, or the execution of arbitrary code. These vulnerbilities affect a wide range of components: TLS and certificate validation (ssl, public_key), SSH (ssh), network clients and servers (inets, ftp, epmd, kernel), runtime and libraries (erts, erl_interface, stdlib, megaco). Several of these fixes tighten checks that were previously too permissive, and can cause configurations that worked before to stop working. The most likely to be noticed are: - TLS clients using verify_peer, which is the default, now reject certificates that carry no subjectAltName extension; the customize_hostname_check option does not restore the old behaviour. - Erlang distribution over TLS with the kernel 'check_ip' option now enforces the check that was previously a no-op, so clusters whose nodes are not on the same subnet lose distribution connectivity until the option is unset. - TLS clients that request OCSP stapling now fail the handshake when the server provides no stapled response. - Clients using TLS 1.2 or earlier now abort the handshake if the server sends an ALPN extension that the client did not advertise. - DNS queries made through inet_res now use randomised source ports https://security-tracker.debian.org/tracker/DSA-6464-1
CSIRTS triage
- What
- Multiple vulnerabilities across TLS, SSH, network clients, and runtime components allow denial of service, information disclosure, authentication bypass, and arbitrary code execution.
- Who is affected
- Erlang/OTP deployments using affected versions; TLS clients and SSH components are most impacted.
- Urgency
- High; vulnerabilities span critical subsystems; some fixes restrict previous permissive behavior and may affect production configurations.
- Action
- Upgrade Erlang/OTP to the patched version and review TLS certificate validation and distribution configurations for compatibility.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Erlang/OTP
Get an email when a new Erlang/OTP advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://lists.debian.org/debian-security-announce/2026/msg00375.html
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-288080.54% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-288100.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-321440.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-321470.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-427890.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-427900.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-427910.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-427920.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-470780.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-488550.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [medium] Erlang/OTP: Vulnerability allows File Manipulationcert-bund
- high[UPDATE] [high] Erlang/OTP: Multiple vulnerabilitiescert-bund
- high[NEW] [high] Erlang/OTP: Multiple vulnerabilitiescert-bund
- medium[NEW] [medium] Erlang/OTP: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Erlang/OTP: Multiple vulnerabilitiescert-bund
- medium[UPDATE] [medium] Erlang/OTP: Multiple vulnerabilities allow bypassing security measurescert-bund
- unknownCVE-2026-42792: epmd permanent DoS via EMFILE on accept(2) in ertsmsrc
- highCVE-2026-55953: TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authenticat…msrc
- unknownCVE-2026-58227: TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chainmsrc
- unknownCVE-2026-59251: CVE-2026-59251msrc
- unknownCVE-2026-55737: Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts exter…msrc
- unknownCVE-2026-59251: Allocation of resources without limits in Erlang/OTP public_key certificate path validation al…nvd
More from Debian Security Advisories
- unknownDSA-6465-1 openssl - security update2026-08-25
- unknownDSA-6466-1 linux - security update2026-08-25
- unknownDSA-6463-1 webkit2gtk - security update2026-08-24
- unknownDSA-6462-1 zfs-linux - security update2026-08-24
- unknownDSA-6460-1 openjdk-25 - security update2026-08-23