Skip to content

Update dependency erlang to v29 - #1230

Merged
tpendragon merged 2 commits into
mainfrom
renovate/erlang-29.x
Aug 26, 2026
Merged

Update dependency erlang to v29#1230
tpendragon merged 2 commits into
mainfrom
renovate/erlang-29.x

Conversation

@renovate

@renovate renovate Bot commented May 27, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Update Change
erlang major 27.3.429.0.5
erlang major 27.3.4.1629.0.5

Release Notes

erlang/otp (erlang)

v29.0.5: OTP 29.0.5

Compare Source

Patch Package:           OTP 29.0.5
Git Tag:                 OTP-29.0.5
Date:                    2026-08-04
Trouble Report Id:       OTP-20137, OTP-20275
Seq num:                 GH-11402, PR-11110, PR-11409
System:                  OTP
Release:                 29
Application:             erts-17.0.5, ssh-6.0.4
Predecessor:             OTP 29.0.4

Check out the git tag OTP-29.0.5, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.

erts-17.0.5

The erts-17.0.5 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed a regression in the previous patch release that prevented epmd from binding to localhost.

    Own Id: OTP-20275
    Related Id(s): GH-11402, PR-11409

Full runtime dependencies of erts-17.0.5

kernel-9.0, sasl-3.3, stdlib-4.1

ssh-6.0.4

The ssh-6.0.4 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • The SSH client and server now reject incoming packets not aligned to the cipher block size as required by RFC 4253 §6. For CBC ciphers, a timing-safe "packet discard" mechanism (CVE-2008-5161 mitigation) ensures structural errors are indistinguishable from MAC failures before disconnecting. AEAD and encrypt-then-MAC modes disconnect immediately.

    Own Id: OTP-20137
    Related Id(s): PR-11110

Full runtime dependencies of ssh-6.0.4

crypto-5.7, erts-14.0, kernel-10.3, public_key-1.6.1, runtime_tools-1.15.1, stdlib-8.0

v29.0.4: OTP 29.0.4

Compare Source

Patch Package:           OTP 29.0.4
Git Tag:                 OTP-29.0.4
Date:                    2026-07-27
Trouble Report Id:       OTP-20136, OTP-20143, OTP-20214, OTP-20229,
                         OTP-20237, OTP-20239, OTP-20240, OTP-20241,
                         OTP-20242, OTP-20243, OTP-20244, OTP-20245,
                         OTP-20248, OTP-20250, OTP-20251, OTP-20257,
                         OTP-20258, OTP-20259, OTP-20260, OTP-20261
Seq num:                 CVE-2026-42792, CVE-2026-47078,
                         CVE-2026-54890, CVE-2026-55737,
                         CVE-2026-55953, CVE-2026-58227, ERIERL-1341,
                         GH-11319, GH-11332, GH-11368,
                         GH-SA-622p-qfh6-c352, GH-SA-7xgh-gmgf-q2g7,
                         PR-11239, PR-11297, PR-11303, PR-11323,
                         PR-11330, PR-11331, PR-11333, PR-11334,
                         PR-11336, PR-11337, PR-11341, PR-11343,
                         PR-11369, PR-11372, PR-11374, PR-11386,
                         PR-27944
System:                  OTP
Release:                 29
Application:             compiler-10.0.3, crypto-5.9.2,
                         diameter-2.7.2, erts-17.0.4, megaco-4.9.1,
                         public_key-1.21.4, ssh-6.0.3, ssl-11.7.4,
                         stdlib-8.0.3
Predecessor:             OTP 29.0.3

Check out the git tag OTP-29.0.4, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.

POTENTIAL INCOMPATIBILITIES

  • Mitigated a denial of service attack in epmd.

    Thanks to Ryan Moore for finding and responsibly disclosing this vulnerability to the Erlang/OTP project.

    Own Id: OTP-20136
    Application(s): erts
    Related Id(s): PR-11386, CVE-2026-42792

compiler-10.0.3

The compiler-10.0.3 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • compiler: Fix an internal consistency check failure with setelement

    Own Id: OTP-20261
    Related Id(s): GH-11368, PR-11374

Full runtime dependencies of compiler-10.0.3

crypto-5.1, erts-13.0, kernel-8.4, stdlib-8.0

crypto-5.9.2

The crypto-5.9.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed crash in crypto:macN/5 when supplied MacLength was greater than length of what the underlying hash returned.

    Own Id: OTP-20239
    Related Id(s): PR-11239

  • Fixed segfault in crypto:aead_cipher_init_nif when argument validation fails.

    Own Id: OTP-20241
    Related Id(s): PR-11330

  • Fix cipher key buffer overread for chacha20_poly1305.

    Own Id: OTP-20244
    Related Id(s): PR-11337

Full runtime dependencies of crypto-5.9.2

erts-9.0, kernel-6.0, stdlib-3.9

diameter-2.7.2

The diameter-2.7.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fix infinite loop in diameter_dist:route_session/2 when avp other than Session-Id has zero length.

    Own Id: OTP-20242
    Related Id(s): PR-11331

  • Fix crash in diameter_dist:route_session/2 when Session-Id (code: 263) avp has zero length.

    Own Id: OTP-20243
    Related Id(s): PR-11333

Full runtime dependencies of diameter-2.7.2

erts-10.0, kernel-3.2, ssl-9.0, stdlib-5.0

erts-17.0.4

The erts-17.0.4 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Mitigated a denial of service attack in epmd.

    Thanks to Ryan Moore for finding and responsibly disclosing this vulnerability to the Erlang/OTP project.

    Own Id: OTP-20136
    Related Id(s): PR-11386, CVE-2026-42792

    *** POTENTIAL INCOMPATIBILITY ***

  • Fixed heap corruption when an invalidly encoded tuple with an arity of 2^31 or larger is decoded from Erlang's External Term Format (binary_to_term).

    Own Id: OTP-20214
    Related Id(s): PR-11297, CVE-2026-55737

  • When send_timeout is set and send_timeout_close is set to true, a 'tcp_closed' message is expected when the timeout occurs, but that (message) was not delivered. This has now been fixed.

    Own Id: OTP-20257
    Related Id(s): GH-11319

  • A crafted External Term Format (ETF) payload could crash the runtime system.

    Thanks to Paul Guyot for finding and responsibly disclosing this vulnerability to the Erlang/OTP project.

    Own Id: OTP-20259
    Related Id(s): PR-11386, CVE-2026-54890

  • Fixed a rounding error in 16-bit float conversion.

    Own Id: OTP-20260
    Related Id(s): GH-11332, PR-11334

Full runtime dependencies of erts-17.0.4

kernel-9.0, sasl-3.3, stdlib-4.1

megaco-4.9.1

The megaco-4.9.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed a buffer overflow in the megaco flex scanner C driver. A property parm name exceeding 452 bytes in a text-encoded H.248 message could overflow a fixed-size error buffer, crashing the VM. The sprintf calls have been replaced with bounded snprintf.

    Own Id: OTP-20237
    Related Id(s): GH-SA-7xgh-gmgf-q2g7, PR-11323

Full runtime dependencies of megaco-4.9.1

asn1-3.0, debugger-4.0, erts-12.0, et-1.5, kernel-8.0, runtime_tools-1.8.14, stdlib-2.5

public_key-1.21.4

The public_key-1.21.4 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • A certificate chain with crafted policyMappings extensions could cause exponential memory consumption during path validation, exploitable via TLS handshake. Chains exceeding a node-count cap are now rejected with {bad_cert, policy_tree_exceeded}.

    Own Id: OTP-20251
    Related Id(s): GH-SA-622p-qfh6-c352, PR-11372

Full runtime dependencies of public_key-1.21.4

asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0

ssh-6.0.3

The ssh-6.0.3 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • DH key exchange now enforces strict bounds (1 < e/f < p-1, 1 < K < p-1) on all paths, matching OpenSSH and Go. No interop impact.

    Own Id: OTP-20229
    Related Id(s): PR-11303

  • Validate DH group parameters (P, G) received from the server during DH-GEX key exchange. The client now rejects groups where P is smaller than 2048 bits or G is not in the range (1, P-1). The default minimum in dh_gex_limits has been raised to 2048 on both client and server.

    Own Id: OTP-20258
    Related Id(s): ERIERL-1341, PR-11369

Full runtime dependencies of ssh-6.0.3

crypto-5.7, erts-14.0, kernel-10.3, public_key-1.6.1, runtime_tools-1.15.1, stdlib-8.0

ssl-11.7.4

Note! The ssl-11.7.4 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.

   On a full OTP 29 installation, also the following runtime
   dependency has to be satisfied:
   -- public_key-1.21.1 (first satisfied in OTP 29.0.1)

Fixed Bugs and Malfunctions

  • Add pre TLS-1.3 client side validation of servers algorithm selection being part of clients offered algorithms, preventing in worst case MITM circumventing validation of server certificate tricking the client to trust the malicious MITM as it was a valid server. Note this check is already performed for TLS-1.3 clients.

    Own Id: OTP-20240
    Related Id(s): PR-11336, CVE-2026-55953

  • Prevent invalid cert chains to create cycles in chain building code used to handle chains that could be unordered or contain extraneous certs. This avoids a DoS attack possibility.

    Own Id: OTP-20245
    Related Id(s): PR-11343, CVE-2026-58227

  • Clarify that rsa_psk and anonymous key exchange algorithms are considered legacy. Also harden rsa_psk in same way as normal rsa key exchange.

    Own Id: OTP-20248
    Related Id(s): PR-11341

  • Harden SSL application to conform with best practice and RFC's. This will mostly improve error messages and conserve memory usage.

    Own Id: OTP-20250
    Related Id(s): PR-27944

  • A certificate chain with crafted policyMappings extensions could cause exponential memory consumption during path validation, exploitable via TLS handshake. Chains exceeding a node-count cap are now rejected with {bad_cert, policy_tree_exceeded}.

    Own Id: OTP-20251
    Related Id(s): GH-SA-622p-qfh6-c352, PR-11372

Full runtime dependencies of ssl-11.7.4

crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public_key-1.21.1, runtime_tools-1.15.1, stdlib-7.0

stdlib-8.0.3

The stdlib-8.0.3 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed a bug where zip:unzip/1,2 and zip:extract/1,2 were vulnerable to a relative path traversal attack. A crafted zip archive containing entry names such as ../x/y could have caused files to be written outside the intended extraction directory.

    Thanks to Jonatan Männchen and Zhang Delong for finding and responsibly disclosing this vulnerability to the Erlang/OTP project.

    Own Id: OTP-20143
    Related Id(s): PR-11386, CVE-2026-47078

Full runtime dependencies of stdlib-8.0.3

compiler-5.0, crypto-4.5, erts-16.0.3, kernel-11.0, sasl-3.0, syntax_tools-3.2.1

Thanks to

a1x-an, Jonatan Männchen

v29.0.3: OTP 29.0.3

Compare Source

Patch Package:           OTP 29.0.3
Git Tag:                 OTP-29.0.3
Date:                    2026-07-02
Trouble Report Id:       OTP-20173, OTP-20183, OTP-20185, OTP-20186,
                         OTP-20190, OTP-20191, OTP-20194, OTP-20196,
                         OTP-20197, OTP-20198, OTP-20199, OTP-20200,
                         OTP-20201, OTP-20206, OTP-20207, OTP-20208,
                         OTP-20215, OTP-20216, OTP-20217, OTP-20220,
                         OTP-20222, OTP-20226, OTP-20227, OTP-20230,
                         OTP-20231, OTP-20232, OTP-20233
Seq num:                 CVE-2026-53422, CVE-2026-54886,
                         CVE-2026-54887, CVE-2026-54891,
                         CVE-2026-55950, CVE-2026-55952, ERIERL-1333,
                         GH-SA-7wp4-pc27-2vj9, GH-SA-h9pw-h5w4-h976,
                         PR-11209, PR-11215, PR-11219, PR-11230,
                         PR-11239, PR-11244, PR-11247, PR-11250,
                         PR-11259, PR-11268, PR-11269, PR-11270,
                         PR-11271, PR-11281, PR-11282, PR-11283,
                         PR-11289, PR-11294, PR-11295, PR-11299,
                         PR-11302, PR-11306, PR-11307, PR-11309,
                         PR-11311
System:                  OTP
Release:                 29
Application:             common_test-1.31.1, compiler-10.0.2,
                         crypto-5.9.1, dialyzer-6.0.2, erts-17.0.3,
                         kernel-11.0.3, public_key-1.21.3, ssh-6.0.2,
                         ssl-11.7.3, stdlib-8.0.2
Predecessor:             OTP 29.0.2

Check out the git tag OTP-29.0.3, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.

common_test-1.31.1

The common_test-1.31.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed a crash in ct_netconfc that occurred when the remote server closed the SSH connection during NETCONF subsystem negotiation.

    Own Id: OTP-20191
    Related Id(s): ERIERL-1333, PR-11230

Full runtime dependencies of common_test-1.31.1

compiler-10.0, crypto-4.5, debugger-4.1, erts-7.0, ftp-1.0, inets-6.0, kernel-11.0, observer-2.1, runtime_tools-1.8.16, sasl-2.5, snmp-5.1.2, ssh-4.0, stdlib-8.0, syntax_tools-1.7, tools-3.2, xmerl-1.3.8

compiler-10.0.2

The compiler-10.0.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Several compiler bugs that could crash the compiler or generate incorrect code in rare circumstances have been fixed.

    Own Id: OTP-20222
    Related Id(s): PR-11219

Full runtime dependencies of compiler-10.0.2

crypto-5.1, erts-13.0, kernel-8.4, stdlib-8.0

crypto-5.9.1

The crypto-5.9.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • crypto:compute_key/4 for eddh and crypto:generate_key/2,3 for eddh/eddsa now raise an error:{notsup, Info, Description} exception instead of returning the atom notsup when the underlying cryptolib lacks support.

    Own Id: OTP-20215
    Related Id(s): PR-11302

Full runtime dependencies of crypto-5.9.1

erts-9.0, kernel-6.0, stdlib-3.9

dialyzer-6.0.2

The dialyzer-6.0.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fix a bug with native record sets in erl_types.erl

    Own Id: OTP-20201

Full runtime dependencies of dialyzer-6.0.2

compiler-10.0, erts-12.0, kernel-8.0, stdlib-5.0, syntax_tools-2.0

erts-17.0.3

The erts-17.0.3 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed an undefined behavior in the internal erts_qsort() function, which could have been the cause of a beam crash seen when updating large maps.

    Own Id: OTP-20185
    Related Id(s): PR-11215

  • Calculating bxor of the largest supported positive integer (erlang:system_info(max_integer)) and -1 would return [] instead of a raising a system_limit exception.

    Own Id: OTP-20208
    Related Id(s): PR-11269

  • Fix possible race between ets:delete/1 and terminating process with a fixation on the same table.

    Own Id: OTP-20217
    Related Id(s): PR-11283

  • A few code generation issues for the JIT on AArch64 (ARM64) have been fixed.

    For all platforms, the loader will reject some invalid BEAM files earlier.

    Own Id: OTP-20226
    Related Id(s): PR-11299

  • On 32-bit computers, the md5 BIFs would return an incorrect MD5 checksum for data of size 4GiB or more.

    Own Id: OTP-20227
    Related Id(s): PR-11289

Full runtime dependencies of erts-17.0.3

kernel-9.0, sasl-3.3, stdlib-4.1

kernel-11.0.3

The kernel-11.0.3 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • inet:info/1 could crash when calling for a closing (port) socket.

    Own Id: OTP-20173

  • Handling of the truncation bit in inet_res has been fixed so it properly falls back to querying over TCP after a truncated UDP reply.

    This fixes a bug introduced in OTP-28.4.2 - kernel-10.6.2 making a truncated UDP answer fail to parse and never execute the fallback, instead the name resolve operation fails.

    Own Id: OTP-20199
    Related Id(s): PR-11247

Full runtime dependencies of kernel-11.0.3

crypto-5.8, erts-17.0, sasl-3.0, stdlib-8.0

public_key-1.21.3

The public_key-1.21.3 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Hardened OCSP response verification by using constant-time hash comparisons and rejecting responses exceeding 100 KB before ASN.1 decoding.

    Own Id: OTP-20197
    Related Id(s): PR-11239

Full runtime dependencies of public_key-1.21.3

asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0

ssh-6.0.2

The ssh-6.0.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed a path-existence oracle in the SFTP server where SSH_FXP_REALPATH requests with .. components could bypass the configured root directory isolation, allowing an authenticated client to determine whether arbitrary paths exist on the host filesystem.

    Own Id: OTP-20183
    Related Id(s): GH-SA-h9pw-h5w4-h976, PR-11294, CVE-2026-53422

  • Fixed an infinite loop in the SFTP server triggered when receiving SSH_MSG_CHANNEL_EXTENDED_DATA on an SFTP channel, which caused the channel process to spin indefinitely on CPU without consuming its message queue.

    Own Id: OTP-20186
    Related Id(s): GH-SA-7wp4-pc27-2vj9, PR-11295, CVE-2026-54886

  • Fixed mlkem768x25519 hybrid key exchange failing intermittently with "incorrect signature" when the X25519 shared secret had a leading zero byte. The shared secret is now encoded as a fixed-width 32-byte string per the specification.

    Own Id: OTP-20196
    Related Id(s): PR-11209

  • Fixed a race condition where SSH keepalive responses could be matched to unrelated pending requests due to incorrect request queue ordering. Requests are now matched in the order they were sent.

    Own Id: OTP-20198
    Related Id(s): PR-11244

  • The SFTP server now caps the read length in SSH_FXP_READ requests to 255 KiB (matching OpenSSH's SFTP_MAX_READ_LENGTH), preventing excessive memory allocation when clients request large reads.

    Own Id: OTP-20200
    Related Id(s): PR-11259

  • Removed a server-side workaround (OTP-14827, introduced in OTP 20) that accepted SHA-1 user-auth signatures from clients identifying as OpenSSH 7.x when rsa-sha2-* was negotiated. The workaround addressed a distro-specific build issue in 2017 that no longer exists. Clients affected by this removal (extremely unlikely — requires a 10-year-old unpatched OpenSSH build) will see authentication failures and must upgrade.

    Own Id: OTP-20206
    Related Id(s): PR-11268

Full runtime dependencies of ssh-6.0.2

crypto-5.7, erts-14.0, kernel-10.3, public_key-1.6.1, runtime_tools-1.15.1, stdlib-8.0

ssl-11.7.3

Note! The ssl-11.7.3 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.

   On a full OTP 29 installation, also the following runtime
   dependency has to be satisfied:
   -- public_key-1.21.1 (first satisfied in OTP 29.0.1)

Fixed Bugs and Malfunctions

  • Correct small behavior bugs that occasionally could cause DTLS connection errors, unwanted behavior for legacy DHE_DSS, hiding of a distribution config error, and possible unorderly process tree shutdown.

    Own Id: OTP-20190
    Related Id(s): PR-11250

  • Initialize DTLS cookie to random value to avoid DoS attack with forged cookie during startup window.

    Own Id: OTP-20194
    Related Id(s): PR-11271, CVE-2026-54887

  • Guard TLS client for MITM injection of application data during "plain-text-window" during handshake.

    Own Id: OTP-20207
    Related Id(s): PR-11270, CVE-2026-54891

  • Improve error handling of TLS PSK sending ILLIGAL_PARMETER alert if binders and PSK-identities are not matched. Also mend recovery mechanism of ticket and session stores to be as resilient as possible to intermediate bugs.

    Own Id: OTP-20216
    Related Id(s): PR-11282, CVE-2026-55952

  • Fix race condition that could be used to DoS attack DTLS servers.

    Own Id: OTP-20220
    Related Id(s): PR-11306, CVE-2026-55950

  • A TLS-1.3 stateless session ticket with obfuscated_ticket_age set to zero was incorrectly accepted without checking the server-side ticket lifetime or the RFC 8446 Section 8.3 freshness window. The server now always validates ticket age using its own timestamp regardless of the client-reported age value.

    Own Id: OTP-20230
    Related Id(s): PR-11307

  • TLS-1.3 client rejects a second HelloRetryRequest as requiered in RFC 8446 Section 4.1.4

    Own Id: OTP-20231
    Related Id(s): PR-11309

  • A busy client node could self-trigger a ticket store crash if unlucky with scheduling if auto mode is used.

    Own Id: OTP-20232
    Related Id(s): PR-11311

  • Correct spec for CRL API

    Own Id: OTP-20233
    Related Id(s): PR-11281

Full runtime dependencies of ssl-11.7.3

crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public_key-1.21.1, runtime_tools-1.15.1, stdlib-7.0

stdlib-8.0.2

The stdlib-8.0.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Several compiler bugs that could crash the compiler or generate incorrect code in rare circumstances have been fixed.

    Own Id: OTP-20222
    Related Id(s): PR-11219

Full runtime dependencies of stdlib-8.0.2

compiler-5.0, crypto-4.5, erts-16.0.3, kernel-11.0, sasl-3.0, syntax_tools-3.2.1

Thanks to

Cole Christensen, Nick Krichevsky, Stefan Grundmann

v29.0.2: OTP 29.0.2

Compare Source

Patch Package:           OTP 29.0.2
Git Tag:                 OTP-29.0.2
Date:                    2026-06-10
Trouble Report Id:       OTP-20057, OTP-20149, OTP-20150, OTP-20151,
                         OTP-20153, OTP-20154, OTP-20155, OTP-20156,
                         OTP-20160, OTP-20161, OTP-20162, OTP-20163,
                         OTP-20165, OTP-20166, OTP-20170, OTP-20172,
                         OTP-20174, OTP-20178, OTP-20181
Seq num:                 CVE-2026-48855, CVE-2026-48856,
                         CVE-2026-48858, CVE-2026-48859,
                         CVE-2026-48860, CVE-2026-49759,
                         CVE-2026-49760, GH-11104, GH-11105, GH-11152,
                         GH-SA-24cv-hwgr-37fq, GH-SA-3w6p-vwhf-wvp4,
                         GH-SA-6f4f-chj5-5g97, GH-SA-gp7x-mfv6-52cv,
                         GH-SA-m75x-4vwg-ggjh, GH-SA-pv7g-pjrq-x2fh,
                         GH-SA-xcxj-5pg2-v72j, PR-11141, PR-11145,
                         PR-11146, PR-11148, PR-11154, PR-11157,
                         PR-11168, PR-11181, PR-11186, PR-11192,
                         PR-11193, PR-11195, PR-11199, PR-11205,
                         PR-11212, PR-1234, PR-27384
System:                  OTP
Release:                 29
Application:             dialyzer-6.0.1, diameter-2.7.1,
                         erl_interface-5.8.1, erts-17.0.2, ftp-1.2.6,
                         inets-9.7.1, kernel-11.0.2, mnesia-4.26.1,
                         public_key-1.21.2, ssh-6.0.1, ssl-11.7.2,
                         stdlib-8.0.1, tools-4.2.1
Predecessor:             OTP 29.0.1

Check out the git tag OTP-29.0.2, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.

dialyzer-6.0.1

The dialyzer-6.0.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fix native record bugs in Dialyzer

    Own Id: OTP-20178
    Related Id(s): PR-11199

Full runtime dependencies of dialyzer-6.0.1

compiler-10.0, erts-12.0, kernel-8.0, stdlib-5.0, syntax_tools-2.0

diameter-2.7.1

The diameter-2.7.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed return value documentation of diameter:service_info(SvcName, statistics)

    Own Id: OTP-20150
    Related Id(s): GH-11105, PR-11146

Full runtime dependencies of diameter-2.7.1

erts-10.0, kernel-3.2, ssl-9.0, stdlib-5.0

erl_interface-5.8.1

The erl_interface-5.8.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

erts-17.0.2

The erts-17.0.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • A buffer overflow error when parsing SCTP ERROR or ABORT chunks has been fixed.

    This could lead to stack corruption and VM crash, but ultimately with hard work by an attacker be refined into maybe even remote code execution.

    Own Id: OTP-20165
    Related Id(s): GH-SA-6f4f-chj5-5g97, PR-1234, CVE-2026-49759

Full runtime dependencies of erts-17.0.2

kernel-9.0, sasl-3.3, stdlib-4.1

ftp-1.2.6

The ftp-1.2.6 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • FTP client default connections that use the so called passive mode of FTP fails to properly validating the response IP of the server, hence a malicious or compromised FTP server could redirect the data connection to an arbitrary host, enabling s server-side request forgery (SSRF) and FTP bounce attacks.

    Own Id: OTP-20166
    Related Id(s): GH-SA-24cv-hwgr-37fq, PR-11186, CVE-2026-48858

Full runtime dependencies of ftp-1.2.6

erts-7.0, kernel-6.0, runtime_tools-1.15.1, ssl-10.2, stdlib-3.5

inets-9.7.1

The inets-9.7.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • The HTTP client (httpc) now removes Authorization, Proxy-Authorization, Cookie, Referer, and Origin headers when following a redirect to a different host or port. Previously these headers were forwarded verbatim, potentially leaking credentials to unintended targets.

    This follows the requirements of RFC 9110 §15.4.

    Own Id: OTP-20155
    Related Id(s): GH-SA-m75x-4vwg-ggjh, PR-11212, CVE-2026-48856

Full runtime dependencies of inets-9.7.1

erts-14.0, kernel-9.0, mnesia-4.12, public_key-1.13, runtime_tools-1.8.14, ssl-9.0, stdlib-5.0, stdlib-6.0

kernel-11.0.2

The kernel-11.0.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • gen_tcp_socket accept should explicitly inherit the same options as plain gen_tcp.

    Own Id: OTP-20057

Full runtime dependencies of kernel-11.0.2

crypto-5.8, erts-17.0, sasl-3.0, stdlib-8.0

mnesia-4.26.1

The mnesia-4.26.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed docs of mnesia:write/3 to clarify when a transaction can terminate.

    Own Id: OTP-20149
    Related Id(s): GH-11104, PR-11145

Full runtime dependencies of mnesia-4.26.1

erts-9.0, kernel-5.3, stdlib-5.0

public_key-1.21.2

The public_key-1.21.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Add missing macro reference for legacy algorithms md5 and sha224. This mainly improves error handling.

    Own Id: OTP-20172
    Related Id(s): PR-11195

Full runtime dependencies of public_key-1.21.2

asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0

ssh-6.0.1

The ssh-6.0.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed a timing-based username enumeration vulnerability during password authentication with the user_passwords option. A dummy PBKDF2 computation is now performed for invalid usernames to match the response time of valid ones.

    Own Id: OTP-20153
    Related Id(s): GH-SA-3w6p-vwhf-wvp4, PR-11157, CVE-2026-48859

  • Fixed SSH_FXP_READLINK handler in ssh_sftpd to strip the backend root prefix from symlink targets before returning them to the client, preventing disclosure of the server's absolute filesystem path when the root option is configured.

    Own Id: OTP-20162
    Related Id(s): GH-SA-pv7g-pjrq-x2fh, PR-11192, CVE-2026-48855

  • Fixed a race condition where SSH keep-alive responses could consume pending channel open requests, causing channel setup to fail silently.

    Own Id: OTP-20181
    Related Id(s): PR-11205

Full runtime dependencies of ssh-6.0.1

crypto-5.7, erts-14.0, kernel-10.3, public_key-1.6.1, runtime_tools-1.15.1, stdlib-8.0

ssl-11.7.2

Note! The ssl-11.7.2 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.

   On a full OTP 29 installation, also the following runtime
   dependency has to be satisfied:
   -- public_key-1.21.1 (first satisfied in OTP 29.0.1)

Fixed Bugs and Malfunctions

  • Fix miscellanies issues that could cause unnecessary memory consumption and in some less common scenarios or configurations cause connection failures.

    Own Id: OTP-20154
    Related Id(s): PR-11148

  • Erlang distribution over TLS run with the kernel 'check_ip' flag now properly enforce connecting nodes to be on the same LAN.

    Own Id: OTP-20156
    Related Id(s): GH-SA-gp7x-mfv6-52cv, PR-11181, CVE-2026-48860

  • Enhance error message, by fixing typo of atom in new error message related to `public_key` CVE-2026-42790 solution.

    Own Id: OTP-20161
    Related Id(s): PR-11148

  • Corrected SNI handling for TLS-1.3 only server, could cause connection failures if supported signature algorithms where changed by SNI option update.

    Own Id: OTP-20174
    Related Id(s): PR-27384

Full runtime dependencies of ssl-11.7.2

crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public_key-1.21.1, runtime_tools-1.15.1, stdlib-7.0

stdlib-8.0.1

The stdlib-8.0.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fix a bug where a tuple record operation within a native record anonymous update can crash.

    Own Id: OTP-20151
    Related Id(s): PR-11141

  • Fixed some bugs in io_lib:bformat/2 and native record printing.

    Own Id: OTP-20170
    Related Id(s): PR-11154

Full runtime dependencies of stdlib-8.0.1

compiler-5.0, crypto-4.5, erts-16.0.3, kernel-11.0, sasl-3.0, syntax_tools-3.2.1

tools-4.2.1

The tools-4.2.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Xref could crash instead of returning an appropriate error tuple when asked to open a BEAM file without debug information but with a moduledoc(false) attribute.

    Own Id: OTP-20163
    Related Id(s): GH-11152, PR-11168

Full runtime dependencies of tools-4.2.1

compiler-8.5, crypto-5.9, erts-15.0, kernel-10.0, public_key-1.21, runtime_tools-2.1, stdlib-6.0

Thanks to

John Downey, Jonatan Männchen

v29.0.1: OTP 29.0.1

Compare Source

Patch Package:           OTP 29.0.1
Git Tag:                 OTP-29.0.1
Date:                    2026-05-27
Trouble Report Id:       OTP-20112, OTP-20129, OTP-20130, OTP-20134,
                         OTP-20138, OTP-20139, OTP-20140, OTP-20141,
                         OTP-20146
Seq num:                 CVE-2026-42789, CVE-2026-42790, ERIERL-1321,
                         GH-11088, PR-11007, PR-11089, PR-11100,
                         PR-11107, PR-11123, PR-11124, PR-11125,
                         PR-11135, PR-11136
System:                  OTP
Release:                 29
Application:             compiler-10.0.1, erts-17.0.1, kernel-11.0.1,
                         public_key-1.21.1, snmp-5.20.4, ssl-11.7.1
Predecessor:             OTP 29.0

Check out the git tag OTP-29.0.1, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.

POTENTIAL INCOMPATIBILITIES

  • 'public_key', Adhere to RFC 9525, and remove support for legacy fallback to check hostname against subject common name. Also improve error handling creating two separate errors for name constraint check for subject names and subject alternative names.

    'ssl'. Error handling is slightly changed to better reflect public_key behaviour.

    Own Id: OTP-20130
    Application(s): public_key, ssl
    Related Id(s): PR-11124, CVE-2026-42790

compiler-10.0.1

The compiler-10.0.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • In rare circumstances, optimization of boolean expressions could invert the boolean value.

    Own Id: OTP-20140
    Related Id(s): GH-11088, PR-11089

  • The compiler could crash when compiling code using native records in certain ways.

    Own Id: OTP-20146
    Related Id(s): PR-11135

Full runtime dependencies of compiler-10.0.1

crypto-5.1, erts-13.0, kernel-8.4, stdlib-8.0

erts-17.0.1

The erts-17.0.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Comparison of two native records could return an incorrect result or crash the runtime system.

    Own Id: OTP-20139
    Related Id(s): PR-11107

Full runtime dependencies of erts-17.0.1

kernel-9.0, sasl-3.3, stdlib-4.1

kernel-11.0.1

The kernel-11.0.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • SCTP peeloff of an IPv6 socket, the peeled-off socket does not inherit the parent options as expected.

    Own Id: OTP-20134
    Related Id(s): PR-11007

Full runtime dependencies of kernel-11.0.1

crypto-5.8, erts-17.0, sasl-3.0, stdlib-8.0

public_key-1.21.1

The public_key-1.21.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • OCSP responder certificates are now checked for expiration before being accepted as authorized responders. Previously, expired or not-yet-valid responder certificates were incorrectly accepted when verifying OCSP responses.

    Own Id: OTP-20112
    Related Id(s): PR-11136

  • Corrected basic constraint path validation check in accordance to RFC 5280.

    Own Id: OTP-20129
    Related Id(s): PR-11123, CVE-2026-42789

  • 'public_key', Adhere to RFC 9525, and remove support for legacy fallback to check hostname against subject common name. Also improve error handling creating two separate errors for name constraint check for subject names and subject alternative names.

    'ssl'. Error handling is slightly changed to better reflect public_key behaviour.

    Own Id: OTP-20130
    Related Id(s): PR-11124, CVE-2026-42790

    *** POTENTIAL INCOMPATIBILITY ***

Full runtime dependencies of public_key-1.21.1

asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0

snmp-5.20.4

The snmp-5.20.4 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed a bug in snmpm_usm:generate_outgoing_msg/5 that caused a badmatch crash when constructing an error response for an unknown user/engineID combination.

    Own Id: OTP-20138
    Related Id(s): ERIERL-1321, PR-11100

Full runtime dependencies of snmp-5.20.4

asn1-5.4, crypto-4.6, erts-12.0, kernel-8.0, mnesia-4.12, runtime_tools-1.8.14, stdlib-5.0

ssl-11.7.1

Note! The ssl-11.7.1 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.

   On a full OTP 29 installation, also the following runtime
   dependency has to be satisfied:
   -- public_key-1.21.1 (first satisfied in OTP 29.0.1)

Fixed Bugs and Malfunctions

  • 'public_key', Adhere to RFC 9525, and remove support for legacy fallback to check hostname against subject common name. Also improve error handling creating two separate errors for name constraint check for subject names and subject alternative names.

    'ssl'. Error handling is slightly changed to better reflect public_key behaviour.

    Own Id: OTP-20130
    Related Id(s): PR-11124, CVE-2026-42790

    *** POTENTIAL INCOMPATIBILITY ***

  • Could cause server to terminate a connection without an alert towards a bad client.

    Own Id: OTP-20141
    Related Id(s): PR-11125

Full runtime dependencies of ssl-11.7.1

crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public_key-1.21.1, runtime_tools-1.15.1, stdlib-7.0

Thanks to

Martin Hässler, Paul Guyot

v28.4.3: OTP 28.4.3

Compare Source

Patch Package:           OTP 28.4.3
Git Tag:                 OTP-28.4.3
Date:                    2026-04-21
Trouble Report Id:       OTP-20081, OTP-20086, OTP-20104
Seq num:                 #&#8203;10968, CVE-2026-32147, PR-10985, PR-11027
System:                  OTP
Release:                 28
Application:             kernel-10.6.3, ssh-5.5.2
Predecessor:             OTP 28.4.2

Check out the git tag OTP-28.4.3, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.

OTP-28.4.3

Fixed Bugs and Malfunctions

  • Fix the otp_patch_apply script to properly handle installation of documentation for OTP versions with more than one digit in version parts less significant than the major version.

    Own Id: OTP-20086
    Related Id(s): PR-10985

kernel-10.6.3

The kernel-10.6.3 application can be applied independently of other applications on a full OTP 28 installation.

Fixed Bugs and Malfunctions

  • On Windows, sockets has to be bound when using 'socket'. Therefor when using gen_tcp with inet_backend = socket, gen_tcp_socket bind even if the caller has not provided an explicit bind address. In that case it attempts to locate a "proper" address on its own. But if the connect address is the loopback address, this could lead to an attempt to bind to an external interface. So, this has now been changed so that if the connect address is the loopback address, the loopback address will also be used when binding.

    Own Id: OTP-20104
    Related Id(s): #​10968

Full runtime dependencies of kernel-10.6.3

crypto-5.0, erts-15.2.5, sasl-3.0, stdlib-7.0

ssh-5.5.2

Note! The ssh-5.5.2 application cannot be applied independently of other applications on an arbitrary OTP 28 installation.

   On a full OTP 28 installation, also the following runtime
   dependency has to be satisfied:
   -- crypto-5.7 (first satisfied in OTP 28.1)

Fixed Bugs and Malfunctions

  • Fixed a vulnerability in the SFTP server where file attributes could be modified outside the configured root directory. When using FSETSTAT on an open file handle, the operation used the path stored in the handle without verifying it was within the root directory, allowing attribute changes to files outside the chroot boundary.

    Thanks to John Downey.

    Own Id: OTP-20081
    Related Id(s): PR-11027, CVE-2026-32147

Full runtime dependencies of ssh-5.5.2

crypto-5.7, erts-14.0, kernel-10.3, public_key-1.6.1, runtime_tools-1.15.1, stdlib-5.0, stdlib-6.0

v28.4.2: OTP 28.4.2

Compare Source

Patch Package:           OTP 28.4.2
Git Tag:                 OTP-28.4.2
Date:                    2026-04-07
Trouble Report Id:       OTP-19506, OTP-19889, OTP-19931, OTP-20027,
                         OTP-20037, OTP-20042, OTP-20044, OTP-20046,
                         OTP-20047, OTP-20049, OTP-20050, OTP-20052,
                         OTP-20053, OTP-20056, OTP-20060, OTP-20064,
                         OTP-20065, OTP-20068
Seq num:                 CVE-2026-28810, CVE-2026-32144, ERIERL-1310,
                         ERIERL-1311, ERIERL-1312, GH-10454, GH-10562,
                         GH-10606, GH-10785, GH-10876, GH-10901,
                         GH-7156, GH-9476, PR-10456, PR-10569,
                         PR-10620, PR-10788, PR-10864, PR-10866,
                         PR-10867, PR-10873, PR-10874, PR-10889,
                         PR-10893, PR-10899, PR-10904, PR-10906,
                         PR-10911, PR-10941, PR-9481
System:                  OTP
Release:                 28
Application:             compiler-9.0.6, erts-16.3.1, eunit-2.10.3,
                         inets-9.6.2, kernel-10.6.2,
                         public_key-1.20.3, sasl-4.3.2, snmp-5.20.2,
                         ssl-11.5.4
Predecessor:             OTP 28.4.1

Check out the git tag OTP-28.4.2, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.

POTENTIAL INCOMPATIBILITIES

  • When OCSP stapling is enabled via the {stapling, staple} or {stapling, #{...}} options, the handshake now fails if the server does not provide an OCSP stapled response.

    Previously, a missing OCSP staple was silently accepted (soft-fail). Since Erlang/OTP only supports OCSP via stapling with no fallback to direct OCSP queries or CRL checking, soft-fail meant no revocation check at all.

    Applications that need the previous soft-fail behavior can use a custom verify_fun that accepts {bad_cert, missing_ocsp_staple}.

    Own Id: OTP-20064
    Application(s): ssl
    Related Id(s): [PR-10941], [CVE-2026-32144]

compiler-9.0.6

The compiler-9.0.6 application can be applied independently of other applications on a full OTP 28 installation.

Fixed Bugs and Malfunctions

  • The type inference for maps:from_list/1 was incorrect: when the provided list was statically known to be bogus when non-empty (e.g. a list of atoms), the compiler assumed it would also fail when the list was empty.

    Own Id: OTP-19506
    Related Id(s): [GH-9476], [PR-9481]

  • Fixed a bug in the type analysis pass that could erroneously eliminate code blocks.

    Own Id: OTP-19931
    Related Id(s): [GH-10562], [PR-10569]

  • A binary as the value of a -moduledoc() attribute would be silently ignored.

    Own Id: OTP-20065
    Related Id(s): [GH-10901], [PR-10904]

Full runtime dependencies of compiler-9.0.6

crypto-5.1, erts-13.0, kernel-8.4, stdlib-6.0

erts-16.3.1

The erts-16.3.1 application can be applied independently of other applications on a full OTP 28 installation.

Fixed Bugs and Malfunctions

  • Fixed a JIT bug that miscompiled expressions like X * X + X * X.

    Own Id: OTP-19889
    Related Id(s): [GH-10454], [PR-10456]

  • Fixed bug on windows that made tools dialyzer, erlc and typer unusable in powershell or cmd.exe, when there are spaces in the installation path.

    Own Id: OTP-20027
    Related Id(s): [PR-10620]

  • Fixed a bug with prim_tty that could occur on windows if we cannot get the console mode, mark the TTY as unavailable. This can happen when the input handle is a pipe, but the output handle is a console.

    Own Id: OTP-20060
    Related Id(s): [PR-10899]

Full runtime dependencies of erts-16.3.1

kernel-9.0, sasl-3.3, stdlib-4.1

eunit-2.10.3

The eunit-2.10.3 application can be applied independently of other applications on a full OTP 28 installation.

Fixed Bugs and Malfunctions

  • Fixed EUnit {node, ...} instantiation by passing node name (instead of pid) and restored net_kernel auto-start for non-distributed nodes.

    Own Id: OTP-20047
    Related Id(s): [PR-10788]

Full runtime dependencies of eunit-2.10.3

erts-9.0, kernel-8.3, stdlib-6.0

inets-9.6.2

The inets-9.6.2 application can be applied independently of other applications on a full OTP 28 installation.

Fixed Bugs and Malfunctions

  • Fixed authentication bypass in httpd when script_alias maps a URL to a directory outside document_root with mod_auth directory-based access controls. The mod_alias:which_alias/1 function now includes script_alias entries so authorization is evaluated against the correct path before CGI execution. CVE-2026-28808.

    Own Id: OTP-20068

Improvements and New Features

  • Fixed typo in http_server.md guide

    Own Id: OTP-20044
    Related Id(s): [GH-10785], [PR-10867]

  • Expected error accept_socket_timeout in httpd_request_handler now exits gracefully, without generating a crash and supervisor reports.

    Own Id: OTP-20052
    Related Id(s): ERIERL-1310, [PR-10893]

Full runtime dependencies of inets-9.6.2

erts-14.0, kernel-9.0, mnesia-4.12, public_key-1.13, runtime_tools-1.8.14, ssl-9.0, stdlib-5.0, stdlib-6.0

kernel-10.6.2

The kernel-10.6.2 application can be applied independently of other applications on a full OTP 28 installation.

Fixed Bugs and Malfunctions

  • Before this patch, the Erlang/OTP built-in DNS resolver (inet_res) used a sequential, process-global 16-bit transaction ID for UDP queries and did not implement source port randomization. Response validation relied almost entirely on this ID. Together, this made DNS cache poisoning practical for an attacker who can observe one query or predict the next ID. The design conflicted with RFC 5452 recommendations for mitigating forged DNS answers.

    inet_res is intended for use in trusted network environments and with trusted recursive resolvers. Earlier documentation did not clearly state this deployment assumption, which could lead users to deploy the resolver in environments where faked DNS responses are possible.

    Therefore, the documentation is been updated to clarify that inet_res should only be used in trusted networks and with trusted recursive resolvers.

    The implementation is also improved to use strong random DNS transaction IDs and source ports for every DNS transaction. This should give ample protection against brute forcing fake DNS replies, known as DNS cache poisoning, but it still does not protect against, for example, an adversary in the path of the DNS transaction tha

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/erlang-29.x branch from 3b28d7d to 1ca2f83 Compare June 10, 2026 10:07
@renovate
renovate Bot force-pushed the renovate/erlang-29.x branch from 1ca2f83 to 21b960e Compare June 24, 2026 10:37
@renovate
renovate Bot force-pushed the renovate/erlang-29.x branch 2 times, most recently from deef747 to 8ac9bbb Compare July 7, 2026 20:30
@renovate
renovate Bot force-pushed the renovate/erlang-29.x branch from 8ac9bbb to 9f0ec49 Compare July 17, 2026 02:04
@renovate
renovate Bot force-pushed the renovate/erlang-29.x branch 5 times, most recently from fbf13db to 9a21a89 Compare August 11, 2026 13:59
@renovate
renovate Bot force-pushed the renovate/erlang-29.x branch 2 times, most recently from f8a9f79 to 9a80e3b Compare August 21, 2026 01:39
@github-actions

github-actions Bot commented Aug 21, 2026

Copy link
Copy Markdown

Container Scanning Status: ❌ Failure

NAME                     INSTALLED                FIXED IN          TYPE  VULNERABILITY   SEVERITY    EPSS         RISK   
libssl3t64               3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-14456  High        0.6% (46th)  0.5    
openssl                  3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-14456  High        0.6% (46th)  0.5    
openssl-provider-legacy  3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-14456  High        0.6% (46th)  0.5    
bsdutils                 1:2.41-5                 2.41.5-0+deb13u1  deb   CVE-2026-13595  Medium      0.2% (4th)   < 0.1  
libblkid1                2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-13595  Medium      0.2% (4th)   < 0.1  
liblastlog2-2            2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-13595  Medium      0.2% (4th)   < 0.1  
libmount1                2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-13595  Medium      0.2% (4th)   < 0.1  
libsmartcols1            2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-13595  Medium      0.2% (4th)   < 0.1  
libuuid1                 2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-13595  Medium      0.2% (4th)   < 0.1  
login                    1:4.16.0-2+really2.41-5  2.41.5-0+deb13u1  deb   CVE-2026-13595  Medium      0.2% (4th)   < 0.1  
mount                    2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-13595  Medium      0.2% (4th)   < 0.1  
util-linux               2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-13595  Medium      0.2% (4th)   < 0.1  
bsdutils                 1:2.41-5                 2.41.5-0+deb13u1  deb   CVE-2026-27456  Medium      0.1% (1st)   < 0.1  
libblkid1                2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-27456  Medium      0.1% (1st)   < 0.1  
liblastlog2-2            2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-27456  Medium      0.1% (1st)   < 0.1  
libmount1                2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-27456  Medium      0.1% (1st)   < 0.1  
libsmartcols1            2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-27456  Medium      0.1% (1st)   < 0.1  
libuuid1                 2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-27456  Medium      0.1% (1st)   < 0.1  
login                    1:4.16.0-2+really2.41-5  2.41.5-0+deb13u1  deb   CVE-2026-27456  Medium      0.1% (1st)   < 0.1  
mount                    2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-27456  Medium      0.1% (1st)   < 0.1  
util-linux               2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-27456  Medium      0.1% (1st)   < 0.1  
bsdutils                 1:2.41-5                 2.41.3-1          deb   CVE-2025-14104  Negligible  0.2% (9th)   < 0.1  
libblkid1                2.41-5                   2.41.3-1          deb   CVE-2025-14104  Negligible  0.2% (9th)   < 0.1  
liblastlog2-2            2.41-5                   2.41.3-1          deb   CVE-2025-14104  Negligible  0.2% (9th)   < 0.1  
libmount1                2.41-5                   2.41.3-1          deb   CVE-2025-14104  Negligible  0.2% (9th)   < 0.1  
libsmartcols1            2.41-5                   2.41.3-1          deb   CVE-2025-14104  Negligible  0.2% (9th)   < 0.1  
libuuid1                 2.41-5                   2.41.3-1          deb   CVE-2025-14104  Negligible  0.2% (9th)   < 0.1  
login                    1:4.16.0-2+really2.41-5  2.41.3-1          deb   CVE-2025-14104  Negligible  0.2% (9th)   < 0.1  
mount                    2.41-5                   2.41.3-1          deb   CVE-2025-14104  Negligible  0.2% (9th)   < 0.1  
util-linux               2.41-5                   2.41.3-1          deb   CVE-2025-14104  Negligible  0.2% (9th)   < 0.1  
libssl3t64               3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-14457  High        N/A          N/A    
libssl3t64               3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-18798  High        N/A          N/A    
libssl3t64               3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-54874  High        N/A          N/A    
libssl3t64               3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-63072  High        N/A          N/A    
libssl3t64               3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-63075  High        N/A          N/A    
libssl3t64               3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-63076  High        N/A          N/A    
openssl                  3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-14457  High        N/A          N/A    
openssl                  3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-18798  High        N/A          N/A    
openssl                  3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-54874  High        N/A          N/A    
openssl                  3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-63072  High        N/A          N/A    
openssl                  3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-63075  High        N/A          N/A    
openssl                  3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-63076  High        N/A          N/A    
openssl-provider-legacy  3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-14457  High        N/A          N/A    
openssl-provider-legacy  3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-18798  High        N/A          N/A    
openssl-provider-legacy  3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-54874  High        N/A          N/A    
openssl-provider-legacy  3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-63072  High        N/A          N/A    
openssl-provider-legacy  3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-63075  High        N/A          N/A    
openssl-provider-legacy  3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-63076  High        N/A          N/A    
libssl3t64               3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-63074  Medium      N/A          N/A    
openssl                  3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-63074  Medium      N/A          N/A    
openssl-provider-legacy  3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-63074  Medium      N/A          N/A    
bsdutils                 1:2.41-5                 2.41.5-0+deb13u1  deb   CVE-2026-53612  Unknown     N/A          N/A    
bsdutils                 1:2.41-5                 2.41.5-0+deb13u1  deb   CVE-2026-53613  Unknown     N/A          N/A    
bsdutils                 1:2.41-5                 2.41.5-0+deb13u1  deb   CVE-2026-53614  Unknown     N/A          N/A    
bsdutils                 1:2.41-5                 2.41.5-0+deb13u1  deb   CVE-2026-53615  Unknown     N/A          N/A    
libblkid1                2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53612  Unknown     N/A          N/A    
libblkid1                2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53613  Unknown     N/A          N/A    
libblkid1                2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53614  Unknown     N/A          N/A    
libblkid1                2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53615  Unknown     N/A          N/A    
liblastlog2-2            2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53612  Unknown     N/A          N/A    
liblastlog2-2            2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53613  Unknown     N/A          N/A    
liblastlog2-2            2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53614  Unknown     N/A          N/A    
liblastlog2-2            2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53615  Unknown     N/A          N/A    
libmount1                2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53612  Unknown     N/A          N/A    
libmount1                2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53613  Unknown     N/A          N/A    
libmount1                2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53614  Unknown     N/A          N/A    
libmount1                2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53615  Unknown     N/A          N/A    
libsmartcols1            2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53612  Unknown     N/A          N/A    
libsmartcols1            2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53613  Unknown     N/A          N/A    
libsmartcols1            2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53614  Unknown     N/A          N/A    
libsmartcols1            2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53615  Unknown     N/A          N/A    
libssl3t64               3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-63073  Unknown     N/A          N/A    
libssl3t64               3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-75803  Unknown     N/A          N/A    
libuuid1                 2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53612  Unknown     N/A          N/A    
libuuid1                 2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53613  Unknown     N/A          N/A    
libuuid1                 2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53614  Unknown     N/A          N/A    
libuuid1                 2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53615  Unknown     N/A          N/A    
login                    1:4.16.0-2+really2.41-5  2.41.5-0+deb13u1  deb   CVE-2026-53612  Unknown     N/A          N/A    
login                    1:4.16.0-2+really2.41-5  2.41.5-0+deb13u1  deb   CVE-2026-53613  Unknown     N/A          N/A    
login                    1:4.16.0-2+really2.41-5  2.41.5-0+deb13u1  deb   CVE-2026-53614  Unknown     N/A          N/A    
login                    1:4.16.0-2+really2.41-5  2.41.5-0+deb13u1  deb   CVE-2026-53615  Unknown     N/A          N/A    
mount                    2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53612  Unknown     N/A          N/A    
mount                    2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53613  Unknown     N/A          N/A    
mount                    2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53614  Unknown     N/A          N/A    
mount                    2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53615  Unknown     N/A          N/A    
openssl                  3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-63073  Unknown     N/A          N/A    
openssl                  3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-75803  Unknown     N/A          N/A    
openssl-provider-legacy  3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-63073  Unknown     N/A          N/A    
openssl-provider-legacy  3.5.6-1~deb13u2          3.5.7-1~deb13u2   deb   CVE-2026-75803  Unknown     N/A          N/A    
util-linux               2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53612  Unknown     N/A          N/A    
util-linux               2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53613  Unknown     N/A          N/A    
util-linux               2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53614  Unknown     N/A          N/A    
util-linux               2.41-5                   2.41.5-0+deb13u1  deb   CVE-2026-53615  Unknown     N/A          N/A    

@renovate
renovate Bot force-pushed the renovate/erlang-29.x branch from 9a80e3b to 1e809c5 Compare August 26, 2026 20:25
@renovate

renovate Bot commented Aug 26, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@tpendragon
tpendragon merged commit 4cb3fae into main Aug 26, 2026
5 checks passed
@tpendragon
tpendragon deleted the renovate/erlang-29.x branch August 26, 2026 21:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant