Debian Patches

Status for erlang/1:27.3.4.1+dfsg-1+deb13u1

Patch Description Author Forwarded Bugs Origin Last update
clean.patch clean.patch by Sergei Golovan <sgolovan@nes.ru>

Erlang leaves many files after make clean. This patch contains
a hack to remove them.
no
gnu.patch (1) Defines GNU macros not only for Linux but also for any system
with 'gnu' substring in OS name. Fixes FTBFS on GNU/kFreeBSD and GNU/Hurd.

(2) Undefines BSD4_4 for os_mon application for GNU/Hurd;

(3) Undefines AF_LINK for GNU/Hurd;

(4) Switches some PATH_MAX occurrences to MAXPATHLEN;

(5) Adds a workaround for 'erlc -M | sed' being stuck for GNU/Hurd.
Pino Toscano <pino@debian.org> no
javascript.patch Patch drops JavaScript libraries from the binary package. Sergei Golovan no
x32.patch This patch fixes FTBFS for x86_x32 architecture (x86_64 with 32-bit integers, longs and pointers). Sergei Golovan no
doc.patch Patch moves the command line syntax to a separate ``` block, and fixes interpreting | as table column separators. Sergei Golovan no
exdoc.patch Patch fixes FTBFS when using pbuilder. Sergei Golovan no
CVE-2016-1000107.patch A mix of patches to fix CVE-2016-1000107 and to test for it. Upstream (Marcel Lanz <marcellanz@n-1.ch> and Konrad Pietrzak <konrad@erlang.org>) yes debian upstream 2025-09-18
CVE-2025-48038.patch ssh: verify file handle size limit for client data - reject handles exceeding 256 bytes (as specified for SFTP)
- fixes CVE-2025-48038
Upstream (Jakub Witczak <kuba@erlang.org>) no 2025-08-27
CVE-2025-48039.patch ssh: ssh_sftpd verify path size for client data - reject max_path exceeding the 4096 limit or according to other option value
- fix CVE-2025-48039
Upstream (Jakub Witczak <kuba@erlang.org>) no 2025-07-11
CVE-2025-48040.patch ssh: key exchange robustness improvements
- reduce untrusted data processing for non-debug logs
- trim badmatch exceptions to avoid processing potentially malicious data
- terminate with kexinit_error when too many algorithms are received in KEX init message
Jakub Witczak <kuba@erlang.org> no backport, https://github.com/erlang/otp/commit/7cd7abb7e19e16b027eaee6a54e1f6fbbe21181a 2025-08-20
CVE-2025-48041.patch ssh: max_handles option added to ssh_sftpd
- add max_handles option and update tests (1000 by default)
- remove sshd_read_file redundant testcase
Jakub Witczak <kuba@erlang.org> no backport, https://github.com/erlang/otp/commit/5f9af63eec4657a37663828d206517828cb9f288 2025-08-20

All known versions for source package 'erlang'

Links