Home / mailings [USN-8827-1] Erlang vulnerabilities
Posted on 29 September 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8827-1
September 28, 2026
erlang vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in Erlang.
Software Description:
- erlang: Concurrent, real-time, distributed functional language
Details:
It was discovered that the Erlang Port Mapper Daemon did not properly
handle slow connections. A remote attacker could possibly use this issue
to cause a denial of service. (CVE-2026-42792)
It was discovered that Erlang incorrectly handled certain external term
format data, leading to heap corruption. An attacker could possibly use
this issue to cause Erlang to crash, resulting in a denial of service.
This issue only affected Ubuntu 24.04 LTS and Ubuntu 26.04 LTS.
(CVE-2026-55737)
It was discovered that Erlang incorrectly handled invalid external term
format data. An attacker could possibly use this issue to cause Erlang to
crash, resulting in a denial of service. This issue only affected Ubuntu
26.04 LTS. (CVE-2026-54890)
It was discovered that Erlang incorrectly handled certain packet lengths,
leading to a buffer overflow. A remote attacker could possibly use this
issue to cause Erlang to crash or execute arbitrary code. (CVE-2026-75538)
It was discovered that the Erlang Megaco flex scanner incorrectly handled
certain input, leading to a buffer overflow. A remote attacker could
possibly use this issue to cause Erlang to crash or execute arbitrary code.
(CVE-2026-59250)
It was discovered that Erlang TLS clients incorrectly accepted cipher
suites that they had not offered. A remote attacker could possibly use
this issue to intercept and modify TLS communications. (CVE-2026-55953)
It was discovered that Erlang incorrectly handled certain certificate
chains. A remote attacker could possibly use this issue to cause Erlang to
use excessive resources, leading to a denial of service. This issue only
affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-58227)
It was discovered that Erlang incorrectly handled certain certificate
policies. A remote attacker could possibly use this issue to cause Erlang
to use excessive resources, leading to a denial of service. This issue only
affected Ubuntu 26.04 LTS. (CVE-2026-59251)
It was discovered that the Erlang HTTP server incorrectly handled certain
conflicting HTTP framing headers. A remote attacker could possibly use this
issue to smuggle HTTP requests. (CVE-2026-23941, CVE-2026-73812)
It was discovered that the Erlang HTTP server incorrectly handled certain
malformed chunk sizes. A remote attacker could possibly use this issue to
cause Erlang to crash, resulting in a denial of service. (CVE-2026-69664)
It was discovered that the Erlang HTTP server did not properly limit the
size of chunked request bodies. A remote attacker could possibly use this
issue to cause Erlang to use excessive resources, leading to a denial of
service. (CVE-2026-74835)
It was discovered that the Erlang HTTP server incorrectly handled certain
equivalent request paths and differences in character case. A remote
attacker could possibly use this issue to bypass authentication and gain
unauthorized access. (CVE-2026-66835, CVE-2026-73270)
It was discovered that the Erlang HTTP server did not properly limit
simultaneous connections. A remote attacker could possibly use this issue
to cause Erlang to use excessive resources, leading to a denial of service.
This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-70399)
It was discovered that the Erlang HTTP server incorrectly handled header
continuation lines. A remote attacker could possibly use this issue to
smuggle HTTP requests. (CVE-2026-66357)
It was discovered that the Erlang HTTP server incorrectly handled certain
malformed header names. A remote attacker could possibly use this issue to
smuggle HTTP requests. This issue only affected Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS.
(CVE-2026-73276)
It was discovered that the Erlang HTTP server incorrectly handled
incomplete request bodies. A remote attacker could possibly use this issue
to cause Erlang to use excessive resources, leading to a denial of service.
(CVE-2026-71380)
It was discovered that the Erlang HTTP client did not properly limit the
size of HTTP response headers. A malicious HTTP server could possibly use
this issue to cause Erlang to use excessive resources, leading to a denial
of service. (CVE-2026-55951)
It was discovered that Erlang did not properly limit the length of port
numbers when parsing URIs. A remote attacker could possibly use this issue
to cause Erlang to use excessive resources, leading to a denial of service.
This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS,
Ubuntu 24.04 LTS, and Ubuntu 26.04 LTS. (CVE-2026-59696)
It was discovered that the Erlang SNMP application did not properly limit
the size of certain integer values. A remote attacker could possibly use
this issue to cause Erlang to use excessive resources, leading to a denial
of service. (CVE-2026-70405)
It was discovered that the Erlang LDAP client did not properly limit the
length of port numbers in referral URLs. A malicious LDAP server could
possibly use this issue to cause Erlang to use excessive resources, leading
to a denial of service. (CVE-2026-70409)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
erlang-base 1:27.3.4.6+dfsg-1ubuntu0.1
erlang-eldap 1:27.3.4.6+dfsg-1ubuntu0.1
erlang-inets 1:27.3.4.6+dfsg-1ubuntu0.1
erlang-megaco 1:27.3.4.6+dfsg-1ubuntu0.1
erlang-public-key 1:27.3.4.6+dfsg-1ubuntu0.1
erlang-snmp 1:27.3.4.6+dfsg-1ubuntu0.1
erlang-ssl 1:27.3.4.6+dfsg-1ubuntu0.1
Ubuntu 24.04 LTS
erlang-base 1:25.3.2.8+dfsg-1ubuntu4.7
erlang-eldap 1:25.3.2.8+dfsg-1ubuntu4.7
erlang-inets 1:25.3.2.8+dfsg-1ubuntu4.7
erlang-megaco 1:25.3.2.8+dfsg-1ubuntu4.7
erlang-snmp 1:25.3.2.8+dfsg-1ubuntu4.7
erlang-ssl 1:25.3.2.8+dfsg-1ubuntu4.7
Ubuntu 22.04 LTS
erlang-base 1:24.2.1+dfsg-1ubuntu0.7
erlang-eldap 1:24.2.1+dfsg-1ubuntu0.7
erlang-inets 1:24.2.1+dfsg-1ubuntu0.7
erlang-megaco 1:24.2.1+dfsg-1ubuntu0.7
erlang-snmp 1:24.2.1+dfsg-1ubuntu0.7
erlang-ssl 1:24.2.1+dfsg-1ubuntu0.7
Ubuntu 20.04 LTS
erlang-base 1:22.2.7+dfsg-1ubuntu0.5+esm2
Available with Ubuntu Pro
erlang-base-hipe 1:22.2.7+dfsg-1ubuntu0.5+esm2
Available with Ubuntu Pro
erlang-eldap 1:22.2.7+dfsg-1ubuntu0.5+esm2
Available with Ubuntu Pro
erlang-inets 1:22.2.7+dfsg-1ubuntu0.5+esm2
Available with Ubuntu Pro
erlang-megaco 1:22.2.7+dfsg-1ubuntu0.5+esm2
Available with Ubuntu Pro
erlang-snmp 1:22.2.7+dfsg-1ubuntu0.5+esm2
Available with Ubuntu Pro
erlang-ssl 1:22.2.7+dfsg-1ubuntu0.5+esm2
Available with Ubuntu Pro
Ubuntu 18.04 LTS
erlang-base 1:20.2.2+dfsg-1ubuntu2+esm3
Available with Ubuntu Pro
erlang-base-hipe 1:20.2.2+dfsg-1ubuntu2+esm3
Available with Ubuntu Pro
erlang-eldap 1:20.2.2+dfsg-1ubuntu2+esm3
Available with Ubuntu Pro
erlang-inets 1:20.2.2+dfsg-1ubuntu2+esm3
Available with Ubuntu Pro
erlang-megaco 1:20.2.2+dfsg-1ubuntu2+esm3
Available with Ubuntu Pro
erlang-snmp 1:20.2.2+dfsg-1ubuntu2+esm3
Available with Ubuntu Pro
erlang-ssl 1:20.2.2+dfsg-1ubuntu2+esm3
Available with Ubuntu Pro
Ubuntu 16.04 LTS
erlang-base 1:18.3-dfsg-1ubuntu3.1+esm3
Available with Ubuntu Pro
erlang-base-hipe 1:18.3-dfsg-1ubuntu3.1+esm3
Available with Ubuntu Pro
erlang-eldap 1:18.3-dfsg-1ubuntu3.1+esm3
Available with Ubuntu Pro
erlang-inets 1:18.3-dfsg-1ubuntu3.1+esm3
Available with Ubuntu Pro
erlang-megaco 1:18.3-dfsg-1ubuntu3.1+esm3
Available with Ubuntu Pro
erlang-snmp 1:18.3-dfsg-1ubuntu3.1+esm3
Available with Ubuntu Pro
erlang-ssl 1:18.3-dfsg-1ubuntu3.1+esm3
Available with Ubuntu Pro
Ubuntu 14.04 LTS
erlang-base 1:16.b.3-dfsg-1ubuntu2.2+esm2
Available with Ubuntu Pro
erlang-base-hipe 1:16.b.3-dfsg-1ubuntu2.2+esm2
Available with Ubuntu Pro
erlang-eldap 1:16.b.3-dfsg-1ubuntu2.2+esm2
Available with Ubuntu Pro
erlang-inets 1:16.b.3-dfsg-1ubuntu2.2+esm2
Available with Ubuntu Pro
erlang-megaco 1:16.b.3-dfsg-1ubuntu2.2+esm2
Available with Ubuntu Pro
erlang-snmp 1:16.b.3-dfsg-1ubuntu2.2+esm2
Available with Ubuntu Pro
erlang-ssl 1:16.b.3-dfsg-1ubuntu2.2+esm2
Available with Ubuntu Pro
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8827-1
CVE-2026-23941, CVE-2026-42792, CVE-2026-54890, CVE-2026-55737,
CVE-2026-55951, CVE-2026-55953, CVE-2026-58227, CVE-2026-59250,
CVE-2026-59251, CVE-2026-66357, CVE-2026-66835, CVE-2026-69664,
CVE-2026-70399, CVE-2026-71380, CVE-2026-73270, CVE-2026-73276,
CVE-2026-73812, CVE-2026-74835, CVE-2026-75538
Package Information:
https://launchpad.net/ubuntu/+source/erlang/1:27.3.4.6+dfsg-1ubuntu0.1
https://launchpad.net/ubuntu/+source/erlang/1:25.3.2.8+dfsg-1ubuntu4.7
https://launchpad.net/ubuntu/+source/erlang/1:24.2.1+dfsg-1ubuntu0.7
--===============7026387079670982478==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
