OTP 28.5.0.5 patch release fixes two issues: a regression in erts-16.4.0.5 that prevented epmd from binding to localhost, and a security fix in ssh-5.5.2.4 where the SSH client and server now reject packets not aligned to the cipher block size per RFC 4253. The SSH fix includes a timing-safe packet discard mechanism for CBC ciphers as a CVE-2008-5161 mitigation, while AEAD and encrypt-then-MAC modes disconnect immediately on structural errors.
113 Impressions