Skip to content

Update dependency erlang to v29.0.5 - #144

Merged
bbangert merged 1 commit into
mainfrom
renovate/erlang-29.x
Aug 5, 2026
Merged

Update dependency erlang to v29.0.5#144
bbangert merged 1 commit into
mainfrom
renovate/erlang-29.x

Conversation

@renovate

@renovate renovate Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change
erlang tools patch 29.0.329.0.5

Release Notes

erlang/otp (erlang)

v29.0.5

Compare Source

v29.0.4: OTP 29.0.4

Compare Source

Patch Package:           OTP 29.0.4
Git Tag:                 OTP-29.0.4
Date:                    2026-07-27
Trouble Report Id:       OTP-20136, OTP-20143, OTP-20214, OTP-20229,
                         OTP-20237, OTP-20239, OTP-20240, OTP-20241,
                         OTP-20242, OTP-20243, OTP-20244, OTP-20245,
                         OTP-20248, OTP-20250, OTP-20251, OTP-20257,
                         OTP-20258, OTP-20259, OTP-20260, OTP-20261
Seq num:                 CVE-2026-42792, CVE-2026-47078,
                         CVE-2026-54890, CVE-2026-55737,
                         CVE-2026-55953, CVE-2026-58227, ERIERL-1341,
                         GH-11319, GH-11332, GH-11368,
                         GH-SA-622p-qfh6-c352, GH-SA-7xgh-gmgf-q2g7,
                         PR-11239, PR-11297, PR-11303, PR-11323,
                         PR-11330, PR-11331, PR-11333, PR-11334,
                         PR-11336, PR-11337, PR-11341, PR-11343,
                         PR-11369, PR-11372, PR-11374, PR-11386,
                         PR-27944
System:                  OTP
Release:                 29
Application:             compiler-10.0.3, crypto-5.9.2,
                         diameter-2.7.2, erts-17.0.4, megaco-4.9.1,
                         public_key-1.21.4, ssh-6.0.3, ssl-11.7.4,
                         stdlib-8.0.3
Predecessor:             OTP 29.0.3

Check out the git tag OTP-29.0.4, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.

POTENTIAL INCOMPATIBILITIES

  • Mitigated a denial of service attack in epmd.

    Thanks to Ryan Moore for finding and responsibly disclosing this vulnerability to the Erlang/OTP project.

    Own Id: OTP-20136
    Application(s): erts
    Related Id(s): PR-11386, CVE-2026-42792

compiler-10.0.3

The compiler-10.0.3 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • compiler: Fix an internal consistency check failure with setelement

    Own Id: OTP-20261
    Related Id(s): GH-11368, PR-11374

Full runtime dependencies of compiler-10.0.3

crypto-5.1, erts-13.0, kernel-8.4, stdlib-8.0

crypto-5.9.2

The crypto-5.9.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed crash in crypto:macN/5 when supplied MacLength was greater than length of what the underlying hash returned.

    Own Id: OTP-20239
    Related Id(s): PR-11239

  • Fixed segfault in crypto:aead_cipher_init_nif when argument validation fails.

    Own Id: OTP-20241
    Related Id(s): PR-11330

  • Fix cipher key buffer overread for chacha20_poly1305.

    Own Id: OTP-20244
    Related Id(s): PR-11337

Full runtime dependencies of crypto-5.9.2

erts-9.0, kernel-6.0, stdlib-3.9

diameter-2.7.2

The diameter-2.7.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fix infinite loop in diameter_dist:route_session/2 when avp other than Session-Id has zero length.

    Own Id: OTP-20242
    Related Id(s): PR-11331

  • Fix crash in diameter_dist:route_session/2 when Session-Id (code: 263) avp has zero length.

    Own Id: OTP-20243
    Related Id(s): PR-11333

Full runtime dependencies of diameter-2.7.2

erts-10.0, kernel-3.2, ssl-9.0, stdlib-5.0

erts-17.0.4

The erts-17.0.4 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Mitigated a denial of service attack in epmd.

    Thanks to Ryan Moore for finding and responsibly disclosing this vulnerability to the Erlang/OTP project.

    Own Id: OTP-20136
    Related Id(s): PR-11386, CVE-2026-42792

    *** POTENTIAL INCOMPATIBILITY ***

  • Fixed heap corruption when an invalidly encoded tuple with an arity of 2^31 or larger is decoded from Erlang's External Term Format (binary_to_term).

    Own Id: OTP-20214
    Related Id(s): PR-11297, CVE-2026-55737

  • When send_timeout is set and send_timeout_close is set to true, a 'tcp_closed' message is expected when the timeout occurs, but that (message) was not delivered. This has now been fixed.

    Own Id: OTP-20257
    Related Id(s): GH-11319

  • A crafted External Term Format (ETF) payload could crash the runtime system.

    Thanks to Paul Guyot for finding and responsibly disclosing this vulnerability to the Erlang/OTP project.

    Own Id: OTP-20259
    Related Id(s): PR-11386, CVE-2026-54890

  • Fixed a rounding error in 16-bit float conversion.

    Own Id: OTP-20260
    Related Id(s): GH-11332, PR-11334

Full runtime dependencies of erts-17.0.4

kernel-9.0, sasl-3.3, stdlib-4.1

megaco-4.9.1

The megaco-4.9.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed a buffer overflow in the megaco flex scanner C driver. A property parm name exceeding 452 bytes in a text-encoded H.248 message could overflow a fixed-size error buffer, crashing the VM. The sprintf calls have been replaced with bounded snprintf.

    Own Id: OTP-20237
    Related Id(s): GH-SA-7xgh-gmgf-q2g7, PR-11323

Full runtime dependencies of megaco-4.9.1

asn1-3.0, debugger-4.0, erts-12.0, et-1.5, kernel-8.0, runtime_tools-1.8.14, stdlib-2.5

public_key-1.21.4

The public_key-1.21.4 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • A certificate chain with crafted policyMappings extensions could cause exponential memory consumption during path validation, exploitable via TLS handshake. Chains exceeding a node-count cap are now rejected with {bad_cert, policy_tree_exceeded}.

    Own Id: OTP-20251
    Related Id(s): GH-SA-622p-qfh6-c352, PR-11372

Full runtime dependencies of public_key-1.21.4

asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0

ssh-6.0.3

The ssh-6.0.3 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • DH key exchange now enforces strict bounds (1 < e/f < p-1, 1 < K < p-1) on all paths, matching OpenSSH and Go. No interop impact.

    Own Id: OTP-20229
    Related Id(s): PR-11303

  • Validate DH group parameters (P, G) received from the server during DH-GEX key exchange. The client now rejects groups where P is smaller than 2048 bits or G is not in the range (1, P-1). The default minimum in dh_gex_limits has been raised to 2048 on both client and server.

    Own Id: OTP-20258
    Related Id(s): ERIERL-1341, PR-11369

Full runtime dependencies of ssh-6.0.3

crypto-5.7, erts-14.0, kernel-10.3, public_key-1.6.1, runtime_tools-1.15.1, stdlib-8.0

ssl-11.7.4

Note! The ssl-11.7.4 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.

   On a full OTP 29 installation, also the following runtime
   dependency has to be satisfied:
   -- public_key-1.21.1 (first satisfied in OTP 29.0.1)

Fixed Bugs and Malfunctions

  • Add pre TLS-1.3 client side validation of servers algorithm selection being part of clients offered algorithms, preventing in worst case MITM circumventing validation of server certificate tricking the client to trust the malicious MITM as it was a valid server. Note this check is already performed for TLS-1.3 clients.

    Own Id: OTP-20240
    Related Id(s): PR-11336, CVE-2026-55953

  • Prevent invalid cert chains to create cycles in chain building code used to handle chains that could be unordered or contain extraneous certs. This avoids a DoS attack possibility.

    Own Id: OTP-20245
    Related Id(s): PR-11343, CVE-2026-58227

  • Clarify that rsa_psk and anonymous key exchange algorithms are considered legacy. Also harden rsa_psk in same way as normal rsa key exchange.

    Own Id: OTP-20248
    Related Id(s): PR-11341

  • Harden SSL application to conform with best practice and RFC's. This will mostly improve error messages and conserve memory usage.

    Own Id: OTP-20250
    Related Id(s): PR-27944

  • A certificate chain with crafted policyMappings extensions could cause exponential memory consumption during path validation, exploitable via TLS handshake. Chains exceeding a node-count cap are now rejected with {bad_cert, policy_tree_exceeded}.

    Own Id: OTP-20251
    Related Id(s): GH-SA-622p-qfh6-c352, PR-11372

Full runtime dependencies of ssl-11.7.4

crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public_key-1.21.1, runtime_tools-1.15.1, stdlib-7.0

stdlib-8.0.3

The stdlib-8.0.3 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed a bug where zip:unzip/1,2 and zip:extract/1,2 were vulnerable to a relative path traversal attack. A crafted zip archive containing entry names such as ../x/y could have caused files to be written outside the intended extraction directory.

    Thanks to Jonatan Männchen and Zhang Delong for finding and responsibly disclosing this vulnerability to the Erlang/OTP project.

    Own Id: OTP-20143
    Related Id(s): PR-11386, CVE-2026-47078

Full runtime dependencies of stdlib-8.0.3

compiler-5.0, crypto-4.5, erts-16.0.3, kernel-11.0, sasl-3.0, syntax_tools-3.2.1

Thanks to

a1x-an, Jonatan Männchen


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title Update dependency erlang to v29.0.4 Update dependency erlang to v29.0.5 Aug 4, 2026
@renovate
renovate Bot force-pushed the renovate/erlang-29.x branch from 81f9d29 to 174aefb Compare August 4, 2026 16:00
@bbangert
bbangert force-pushed the renovate/erlang-29.x branch from 174aefb to 4a1c6c9 Compare August 5, 2026 18:17
@renovate

renovate Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@bbangert
bbangert merged commit f6eff8d into main Aug 5, 2026
6 checks passed
@bbangert
bbangert deleted the renovate/erlang-29.x branch August 5, 2026 21:50
bbangert added a commit that referenced this pull request Aug 5, 2026
PR #144 bumped erlang in .mise.toml but the workflow OTP_VERSION pins
weren't tracked by renovate, so CI kept running 29.0.3.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
bbangert added a commit that referenced this pull request Aug 5, 2026
PR #144 bumped erlang in .mise.toml but the workflow OTP_VERSION pins
weren't tracked by renovate, so CI kept running 29.0.3.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant