USN-8827-1: Erlang vulnerabilities

Publication date

28 September 2026

Overview

Several security issues were fixed in Erlang.


Packages

  • erlang - Concurrent, real-time, distributed functional language

Details

It was discovered that the Erlang Port Mapper Daemon did not properly
handle slow connections. A remote attacker could possibly use this issue
to cause a denial of service. (CVE-2026-42792)

It was discovered that Erlang incorrectly handled certain external term
format data, leading to heap corruption. An attacker could possibly use
this issue to cause Erlang to crash, resulting in a denial of service.
This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS.
(CVE-2026-55737)

It was discovered that Erlang incorrectly handled invalid external term
format data. An attacker could possibly use this issue to cause Erlang to
crash, resulting in a denial of service. This issue only affected Ubuntu
26.04 LTS. (CVE-2026-54890)

It was discovered that Erlang incorrectly handled certain packet lengths,
leading...

It was discovered that the Erlang Port Mapper Daemon did not properly
handle slow connections. A remote attacker could possibly use this issue
to cause a denial of service. (CVE-2026-42792)

It was discovered that Erlang incorrectly handled certain external term
format data, leading to heap corruption. An attacker could possibly use
this issue to cause Erlang to crash, resulting in a denial of service.
This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS.
(CVE-2026-55737)

It was discovered that Erlang incorrectly handled invalid external term
format data. An attacker could possibly use this issue to cause Erlang to
crash, resulting in a denial of service. This issue only affected Ubuntu
26.04 LTS. (CVE-2026-54890)

It was discovered that Erlang incorrectly handled certain packet lengths,
leading to a buffer overflow. A remote attacker could possibly use this
issue to cause Erlang to crash or execute arbitrary code. (CVE-2026-75538)

It was discovered that the Erlang Megaco flex scanner incorrectly handled
certain input, leading to a buffer overflow. A remote attacker could
possibly use this issue to cause Erlang to crash or execute arbitrary code.
(CVE-2026-59250)

It was discovered that Erlang TLS clients incorrectly accepted cipher
suites that they had not offered. A remote attacker could possibly use
this issue to intercept and modify TLS communications. (CVE-2026-55953)

It was discovered that Erlang incorrectly handled certain certificate
chains. A remote attacker could possibly use this issue to cause Erlang to
use excessive resources, leading to a denial of service. This issue only
affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-58227)

It was discovered that Erlang incorrectly handled certain certificate
policies. A remote attacker could possibly use this issue to cause Erlang
to use excessive resources, leading to a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-59251)

It was discovered that the Erlang HTTP server incorrectly handled certain
conflicting HTTP framing headers. A remote attacker could possibly use this
issue to smuggle HTTP requests. (CVE-2026-23941, CVE-2026-73812)

It was discovered that the Erlang HTTP server incorrectly handled certain
malformed chunk sizes. A remote attacker could possibly use this issue to
cause Erlang to crash, resulting in a denial of service. (CVE-2026-69664)

It was discovered that the Erlang HTTP server did not properly limit the
size of chunked request bodies. A remote attacker could possibly use this
issue to cause Erlang to use excessive resources, leading to a denial of
service. (CVE-2026-74835)

It was discovered that the Erlang HTTP server incorrectly handled certain
equivalent request paths and differences in character case. A remote
attacker could possibly use this issue to bypass authentication and gain
unauthorized access. (CVE-2026-66835, CVE-2026-73270)

It was discovered that the Erlang HTTP server did not properly limit
simultaneous connections. A remote attacker could possibly use this issue
to cause Erlang to use excessive resources, leading to a denial of service.
This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-70399)

It was discovered that the Erlang HTTP server incorrectly handled header
continuation lines. A remote attacker could possibly use this issue to
smuggle HTTP requests. (CVE-2026-66357)

It was discovered that the Erlang HTTP server incorrectly handled certain
malformed header names. A remote attacker could possibly use this issue to
smuggle HTTP requests. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-73276)

It was discovered that the Erlang HTTP server incorrectly handled
incomplete request bodies. A remote attacker could possibly use this issue
to cause Erlang to use excessive resources, leading to a denial of service.
(CVE-2026-71380)

It was discovered that the Erlang HTTP client did not properly limit the
size of HTTP response headers. A malicious HTTP server could possibly use
this issue to cause Erlang to use excessive resources, leading to a denial
of service. (CVE-2026-55951)

It was discovered that Erlang did not properly limit the length of port
numbers when parsing URIs. A remote attacker could possibly use this issue
to cause Erlang to use excessive resources, leading to a denial of service.
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,
Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-59696)

It was discovered that the Erlang SNMP application did not properly limit
the size of certain integer values. A remote attacker could possibly use
this issue to cause Erlang to use excessive resources, leading to a denial
of service. (CVE-2026-70405)

It was discovered that the Erlang LDAP client did not properly limit the
length of port numbers in referral URLs. A malicious LDAP server could
possibly use this issue to cause Erlang to use excessive resources, leading
to a denial of service. (CVE-2026-70409)


Update instructions

After a standard system update you need to reboot your computer to make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute erlang-base –  1:27.3.4.6+dfsg-1ubuntu0.1
erlang-eldap –  1:27.3.4.6+dfsg-1ubuntu0.1
erlang-inets –  1:27.3.4.6+dfsg-1ubuntu0.1
erlang-megaco –  1:27.3.4.6+dfsg-1ubuntu0.1
erlang-public-key –  1:27.3.4.6+dfsg-1ubuntu0.1
erlang-snmp –  1:27.3.4.6+dfsg-1ubuntu0.1
erlang-ssl –  1:27.3.4.6+dfsg-1ubuntu0.1
24.04 LTS noble erlang-base –  1:25.3.2.8+dfsg-1ubuntu4.7
erlang-eldap –  1:25.3.2.8+dfsg-1ubuntu4.7
erlang-inets –  1:25.3.2.8+dfsg-1ubuntu4.7
erlang-megaco –  1:25.3.2.8+dfsg-1ubuntu4.7
erlang-snmp –  1:25.3.2.8+dfsg-1ubuntu4.7
erlang-ssl –  1:25.3.2.8+dfsg-1ubuntu4.7
22.04 LTS jammy erlang-base –  1:24.2.1+dfsg-1ubuntu0.7
erlang-eldap –  1:24.2.1+dfsg-1ubuntu0.7
erlang-inets –  1:24.2.1+dfsg-1ubuntu0.7
erlang-megaco –  1:24.2.1+dfsg-1ubuntu0.7
erlang-snmp –  1:24.2.1+dfsg-1ubuntu0.7
erlang-ssl –  1:24.2.1+dfsg-1ubuntu0.7
20.04 LTS focal erlang-base –  1:22.2.7+dfsg-1ubuntu0.5+esm2  
erlang-base-hipe –  1:22.2.7+dfsg-1ubuntu0.5+esm2  
erlang-eldap –  1:22.2.7+dfsg-1ubuntu0.5+esm2  
erlang-inets –  1:22.2.7+dfsg-1ubuntu0.5+esm2  
erlang-megaco –  1:22.2.7+dfsg-1ubuntu0.5+esm2  
erlang-snmp –  1:22.2.7+dfsg-1ubuntu0.5+esm2  
erlang-ssl –  1:22.2.7+dfsg-1ubuntu0.5+esm2  
18.04 LTS bionic erlang-base –  1:20.2.2+dfsg-1ubuntu2+esm3  
erlang-base-hipe –  1:20.2.2+dfsg-1ubuntu2+esm3  
erlang-eldap –  1:20.2.2+dfsg-1ubuntu2+esm3  
erlang-inets –  1:20.2.2+dfsg-1ubuntu2+esm3  
erlang-megaco –  1:20.2.2+dfsg-1ubuntu2+esm3  
erlang-snmp –  1:20.2.2+dfsg-1ubuntu2+esm3  
erlang-ssl –  1:20.2.2+dfsg-1ubuntu2+esm3  
16.04 LTS xenial erlang-base –  1:18.3-dfsg-1ubuntu3.1+esm3  
erlang-base-hipe –  1:18.3-dfsg-1ubuntu3.1+esm3  
erlang-eldap –  1:18.3-dfsg-1ubuntu3.1+esm3  
erlang-inets –  1:18.3-dfsg-1ubuntu3.1+esm3  
erlang-megaco –  1:18.3-dfsg-1ubuntu3.1+esm3  
erlang-snmp –  1:18.3-dfsg-1ubuntu3.1+esm3  
erlang-ssl –  1:18.3-dfsg-1ubuntu3.1+esm3  
14.04 LTS trusty erlang-base –  1:16.b.3-dfsg-1ubuntu2.2+esm2  
erlang-base-hipe –  1:16.b.3-dfsg-1ubuntu2.2+esm2  
erlang-eldap –  1:16.b.3-dfsg-1ubuntu2.2+esm2  
erlang-inets –  1:16.b.3-dfsg-1ubuntu2.2+esm2  
erlang-megaco –  1:16.b.3-dfsg-1ubuntu2.2+esm2  
erlang-snmp –  1:16.b.3-dfsg-1ubuntu2.2+esm2  
erlang-ssl –  1:16.b.3-dfsg-1ubuntu2.2+esm2  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›