USN-8827-1: Erlang vulnerabilities
It was discovered that the Erlang Port Mapper Daemon did not properly
handle slow connections. A remote attacker could possibly use this issue
to cause a denial of service. (CVE-2026-42792)
It was discovered that Erlang incorrectly handled certain external term
format data, leading to heap corruption. An attacker could possibly use
this issue to cause Erlang to crash, resulting in a denial of service.
This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS.
(CVE-2026-55737)
It was discovered that Erlang incorrectly handled invalid external term
format data. An attacker could possibly use this issue to cause Erlang to
crash, resulting in a denial of service. This issue only affected Ubuntu
26.04 LTS. (CVE-2026-54890)
It was discovered that Erlang incorrectly handled certain packet lengths,
leading to a buffer overflow. A remote attacker could possibly use this
issue to cause Erlang to crash or execute arbitrary code. (CVE-2026-75538)
It was discovered that the Erlang Megaco flex scanner incorrectly handled
certain input, leading to a buffer overflow. A remote attacker could
possibly use this issue to cause Erlang to crash or execute arbitrary code.
(CVE-2026-59250)
It was discovered that Erlang TLS clients incorrectly accepted cipher
suites that they had not offered. A remote attacker could possibly use
this issue to intercept and modify TLS communications. (CVE-2026-55953)
It was discovered that Erlang incorrectly handled certain certificate
chains. A remote attacker could possibly use this issue to cause Erlang to
use excessive resources, leading to a denial of service. This issue only
affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-58227)
It was discovered that Erlang incorrectly handled certain certificate
policies. A remote attacker could possibly use this issue to cause Erlang
to use excessive resources, leading to a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-59251)
It was discovered that the Erlang HTTP server incorrectly handled certain
conflicting HTTP framing headers. A remote attacker could possibly use this
issue to smuggle HTTP requests. (CVE-2026-23941, CVE-2026-73812)
It was discovered that the Erlang HTTP server incorrectly handled certain
malformed chunk sizes. A remote attacker could possibly use this issue to
cause Erlang to crash, resulting in a denial of service. (CVE-2026-69664)
It was discovered that the Erlang HTTP server did not properly limit the
size of chunked request bodies. A remote attacker could possibly use this
issue to cause Erlang to use excessive resources, leading to a denial of
service. (CVE-2026-74835)
It was discovered that the Erlang HTTP server incorrectly handled certain
equivalent request paths and differences in character case. A remote
attacker could possibly use this issue to bypass authentication and gain
unauthorized access. (CVE-2026-66835, CVE-2026-73270)
It was discovered that the Erlang HTTP server did not properly limit
simultaneous connections. A remote attacker could possibly use this issue
to cause Erlang to use excessive resources, leading to a denial of service.
This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-70399)
It was discovered that the Erlang HTTP server incorrectly handled header
continuation lines. A remote attacker could possibly use this issue to
smuggle HTTP requests. (CVE-2026-66357)
It was discovered that the Erlang HTTP server incorrectly handled certain
malformed header names. A remote attacker could possibly use this issue to
smuggle HTTP requests. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-73276)
It was discovered that the Erlang HTTP server incorrectly handled
incomplete request bodies. A remote attacker could possibly use this issue
to cause Erlang to use excessive resources, leading to a denial of service.
(CVE-2026-71380)
It was discovered that the Erlang HTTP client did not properly limit the
size of HTTP response headers. A malicious HTTP server could possibly use
this issue to cause Erlang to use excessive resources, leading to a denial
of service. (CVE-2026-55951)
It was discovered that Erlang did not properly limit the length of port
numbers when parsing URIs. A remote attacker could possibly use this issue
to cause Erlang to use excessive resources, leading to a denial of service.
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,
Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-59696)
It was discovered that the Erlang SNMP application did not properly limit
the size of certain integer values. A remote attacker could possibly use
this issue to cause Erlang to use excessive resources, leading to a denial
of service. (CVE-2026-70405)
It was discovered that the Erlang LDAP client did not properly limit the
length of port numbers in referral URLs. A malicious LDAP server could
possibly use this issue to cause Erlang to use excessive resources, leading
to a denial of service. (CVE-2026-70409)