Erlang/OTP 29.0.3 patch release fixes numerous bugs across multiple applications including critical security vulnerabilities. The ssl application receives the most fixes, addressing five CVEs: DTLS cookie DoS (CVE-2026-54887), TLS MITM injection during handshake (CVE-2026-54891), TLS PSK parameter mismatch (CVE-2026-55952), DTLS server DoS race condition (CVE-2026-55950), and a TLS-1.3 session ticket validation bypass. The ssh application fixes a path-existence oracle in the SFTP server (CVE-2026-53422) and an infinite loop DoS via extended data messages (CVE-2026-54886). Other fixes include ERTS undefined behavior in qsort causing beam crashes, an ETS race condition, JIT code generation issues on AArch64, and a DNS truncation fallback regression in the kernel.

7m read timeFrom erlangforums.com
Post cover image
Table of contents
common_test-1.31.1compiler-10.0.2crypto-5.9.1dialyzer-6.0.2erts-17.0.3kernel-11.0.3public_key-1.21.3ssh-6.0.2ssl-11.7.3stdlib-8.0.2Thanks to
131 Impressions