SB2026092979 - Ubuntu update for erlang
Published: September 29, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 22 vulnerabilities.
1) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-74835)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the inets httpd server request body handling when processing chunked request bodies with Transfer-Encoding: chunked. A remote attacker can send a request that announces a very large chunk size and continuously stream body data without completing the chunk to cause a denial of service.
Only servers that configure max_body_size to a finite value are vulnerable; default configurations using nolimit are not considered vulnerable.
2) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-70409)
CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper validation of specified quantity in input in the eldap referral-URL port parsing logic when processing a referral URL from a malicious LDAP server. A remote attacker can provide a referral URL with an excessively large decimal port value to cause a denial of service.
The issue involves unbounded conversion between textual decimal representations and arbitrary-precision integers, and the rendering path performs the conversion inside a non-yielding C BIF.
3) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-70405)
CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper validation of specified quantity in input in the snmp BER INTEGER decoder and manager-side logging path when processing untrusted SNMP input containing arbitrarily large integers. A remote attacker can send specially crafted input to cause a denial of service.
The issue involves unbounded integer conversion and rendering of decoded bignums, and the render path runs inside a non-yielding C BIF that can occupy a dirty scheduler thread for the full conversion.
4) Improper Validation of Specified Quantity in Input (CVE-ID: CVE-2026-59696)
CWE-ID: CWE-1284 - Improper Validation of Specified Quantity in Input
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper validation of specified quantity in input in stdlib integer conversion functions and uri_string:parse/1 when processing untrusted URL input or converting unbounded textual decimal representations and arbitrary-precision integers. A remote attacker can send a specially crafted input to cause a denial of service.
The render path performs integer string conversion inside a non-yielding C BIF, which can occupy a dirty scheduler thread for the full conversion, while the parse path is preemptible but can still consume significant processing time with extremely large inputs.
5) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-55951)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the httpc HTTP client when processing HTTP response headers from a server. A remote attacker can send an HTTP response with an arbitrarily large number of headers or very large header values to cause a denial of service.
This affects applications using httpc:request/4,5 to connect to untrusted servers.
6) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-71380)
CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing release of resource after effective lifetime in httpd_request_handler.erl when receiving an HTTP request body after successfully parsing headers. A remote attacker can send valid HTTP headers with a large Content-Length value, transmit a small amount of body data, and then stall the connection to cause a denial of service.
The issue affects httpd in its default configuration when minimum_bytes_per_second is false, allowing stalled connections to hold worker slots indefinitely.
7) Inconsistent interpretation of HTTP requests (CVE-ID: CVE-2026-73276)
CWE-ID: CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to smuggle HTTP requests.
The vulnerability exists due to inconsistent interpretation of HTTP requests in the inets httpd server when processing malformed HTTP headers with whitespace before the colon behind a lenient reverse proxy. A remote attacker can send a specially crafted request to smuggle HTTP requests.
Exploitation requires the server to be deployed behind a reverse proxy that accepts headers containing whitespace before the colon and forwards the request body.
8) Inconsistent interpretation of HTTP requests (CVE-ID: CVE-2026-66357)
CWE-ID: CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to smuggle HTTP requests.
The vulnerability exists due to inconsistent interpretation of HTTP requests in the inets httpd server header parser when handling HTTP requests containing obs-fold header continuation lines. A remote attacker can send a specially crafted request to smuggle HTTP requests.
Exploitation requires the server to be deployed behind a reverse proxy that merges obs-fold continuation lines with the preceding header.
9) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-70399)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the inets httpd server when accepting simultaneous connections. A remote attacker can open a large number of connections and keep them open to cause a denial of service.
Only servers using the default configuration without an explicitly set max_clients value are vulnerable, and no valid request or user interaction is required.
10) Improper Handling of Case Sensitivity (CVE-ID: CVE-2026-73270)
CWE-ID: CWE-178 - Improper Handling of Case Sensitivity
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass authentication and access protected resources.
The vulnerability exists due to improper handling of case sensitivity in the mod_auth module in OTP's inets httpd server when processing requests for protected directory paths on case-insensitive filesystems. A remote attacker can request the same protected resource using different path casing to bypass authentication and access protected resources.
Only deployments on case-insensitive filesystems such as Windows and macOS are vulnerable, and exploitation requires one or more directory blocks configured with mod_auth.
11) Path Equivalence: \'//multiple/leading/slash\' (CVE-ID: CVE-2026-66835)
CWE-ID: CWE-50 - Path Equivalence: \'//multiple/leading/slash\'
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose protected files.
The vulnerability exists due to path equivalence handling in inets httpd mod_auth directory protection when processing request paths with repeated leading slashes. A remote attacker can send a specially crafted request with an extra slash in the path to disclose protected files.
This requires an inets httpd deployment that enforces mod_auth on a directory block.
12) Improper handling of exceptional conditions (CVE-ID: CVE-2026-42792)
CWE-ID: CWE-755 - Improper Handling of Exceptional Conditions
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of exceptional conditions in the do_accept function in erts/epmd/src/epmd_srv.c when handling TCP connection attempts after file descriptor exhaustion. A remote attacker can hold many TCP connections open and trigger accept(2) to return EMFILE or ENFILE to cause a denial of service.
The issue is feasible from a single source because epmd has no per-source-IP connection cap.
13) Missing Release of Resource after Effective Lifetime (CVE-ID: CVE-2026-69664)
CWE-ID: CWE-772 - Missing Release of Resource after Effective Lifetime
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to missing release of resource after effective lifetime in the inets httpd chunked request body handling when processing a chunked request body with a malformed chunk size sent after the headers have already been accepted. A remote attacker can send a specially crafted chunked HTTP request and keep the connection open to cause a denial of service.
The malformed chunk-size line must be delivered in a separate write after the headers are processed; if it arrives together with the headers, the server rejects the request. No special configuration is required, and the issue is reachable in the default configuration.
14) Inconsistent interpretation of HTTP requests (CVE-ID: CVE-2026-73812)
CWE-ID: CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to bypass proxy access controls, poison responses intended for other users, and bypass authentication enforced at the proxy layer.
The vulnerability exists due to inconsistent interpretation of HTTP requests in the inets httpd server when processing requests containing both Transfer-Encoding: chunked and Content-Length headers behind a reverse proxy that prefers Content-Length. A remote attacker can send a specially crafted request to bypass proxy access controls, poison responses intended for other users, and bypass authentication enforced at the proxy layer.
Exploitation requires httpd to be deployed behind a reverse proxy that processes Content-Length preferentially over Transfer-Encoding.
15) Inconsistent interpretation of HTTP requests (CVE-ID: CVE-2026-23941)
CWE-ID: CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to smuggle HTTP requests.
The vulnerability exists due to inconsistent interpretation of HTTP requests in inets httpd Content-Length parsing when processing requests with duplicate Content-Length headers that contain different values. A remote attacker can send a specially crafted request to smuggle HTTP requests.
Exploitation requires httpd to be deployed behind a reverse proxy, load balancer, or CDN that uses a different Content-Length resolution strategy, typically with persistent connections enabled.
16) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-59251)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in certificate path validation when processing a crafted certificate chain during the TLS handshake. A remote attacker can send a specially crafted certificate chain to cause a denial of service.
Any application using TLS certificate path validation through the ssl functionality or direct calls to public_key:pkix_path_validation/3 is affected.
17) Uncontrolled Recursion (CVE-ID: CVE-2026-58227)
CWE-ID: CWE-674 - Uncontrolled Recursion
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in certificate chain path building when processing peer certificate messages during a partial TLS or DTLS handshake. A remote attacker can send a certificate chain containing two mutually cross-signed certificates in unordered form to cause a denial of service.
No authentication or completed handshake is required, and both client and server sides are affected.
18) Algorithm Downgrade (CVE-ID: CVE-2026-55953)
CWE-ID: CWE-757 - Selection of Less-Secure Algorithm During Negotiat
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to read and modify data transmitted over the connection.
The vulnerability exists due to selection of a less-secure algorithm during negotiation in the OTP TLS/DTLS client cipher suite validation logic when processing a ServerHello message. A remote attacker can select an anonymous cipher suite that was not offered by the client to read and modify data transmitted over the connection.
This affects TLS versions up to 1.2 and all DTLS versions, while TLS-1.3 connections are not affected. The issue can bypass the client's verify_peer setting because anonymous cipher suites do not require a server certificate.
19) Out-of-bounds write (CVE-ID: CVE-2026-59250)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds write in the megaco flex scanner C linked-in driver when parsing a text-encoded H.248/Megaco message containing an oversized property parm name. A remote attacker can send a specially crafted message to cause a denial of service.
Only systems configured to use the megaco text codec with the flex scanner option are vulnerable, and the megaco transport port must be reachable. On some environments without runtime hardening, the memory corruption may enable arbitrary code execution.
20) Heap-based buffer overflow (CVE-ID: CVE-2026-75538)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow caused by signed integer overflow in the inet TCP driver when processing TCP packets in {packet,4} mode. A remote attacker can send a specially crafted packet with an incorrect length value to cause a denial of service.
Only TCP ports using the inet driver with {packet,4} mode are affected.
21) Integer underflow (CVE-ID: CVE-2026-54890)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer underflow in the ETF decoder in binary_to_term/1,2 and enif_binary_to_term() when parsing a crafted BIT_BINARY_EXT input. A remote attacker can send a specially crafted payload to cause a denial of service.
The issue causes a full BEAM virtual machine crash rather than a process-level exception, and the [safe] option to binary_to_term/2 does not prevent it.
22) Signed to Unsigned Conversion Error (CVE-ID: CVE-2026-55737)
CWE-ID: CWE-195 - Signed to Unsigned Conversion Error
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to signed to unsigned conversion error in LARGE_TUPLE_EXT decoding in binary_to_term/1 when parsing untrusted external term format data. A remote attacker can supply a specially crafted binary term to cause a denial of service.
The issue affects the Erlang runtime functions decoded_size() and dec_term() in external.c.
Remediation
Install update from vendor's website.