Patch Package OTP 27.3.4.15 Released

Erlang/OTP otp@REDACTED
Mon Jul 27 15:43:13 CEST 2026


Patch Package:           OTP 27.3.4.15
Git Tag:                 OTP-27.3.4.15
Date:                    2026-07-27
Trouble Report Id:       OTP-20136, OTP-20143, OTP-20214, OTP-20229,
                         OTP-20237, OTP-20239, OTP-20240, OTP-20242,
                         OTP-20243, OTP-20244, OTP-20245, OTP-20248,
                         OTP-20250, OTP-20251, OTP-20257, OTP-20258,
                         OTP-20259
Seq num:                 CVE-2026-42792, CVE-2026-47078,
                         CVE-2026-54890, CVE-2026-55737,
                         CVE-2026-55953, CVE-2026-58227, ERIERL-1341,
                         GH-11319, GH-SA-622p-qfh6-c352,
                         GH-SA-7xgh-gmgf-q2g7, PR-11239, PR-11297,
                         PR-11303, PR-11323, PR-11331, PR-11333,
                         PR-11336, PR-11337, PR-11341, PR-11343,
                         PR-11369, PR-11372, PR-11386, PR-27944
System:                  OTP
Release:                 27
Application:             crypto-5.5.3.4, diameter-2.4.1.3,
                         erts-15.2.7.11, megaco-4.7.2.2,
                         public_key-1.17.1.5, ssh-5.2.11.10,
                         ssl-11.2.12.11, stdlib-6.2.2.4
Predecessor:             OTP 27.3.4.14

Check out the git tag OTP-27.3.4.15, and build a full OTP system including
documentation. Apply one or more applications from this build as patches to your
installation using the 'otp_patch_apply' tool. For information on install
requirements, see descriptions for each application version below.

# POTENTIAL INCOMPATIBILITIES

- Mitigated a denial of service attack in epmd.

  Thanks to Ryan Moore for finding and responsibly disclosing this vulnerability
  to the Erlang/OTP project.

  Own Id: OTP-20136
  Application(s): erts
  Related Id(s): PR-11386, CVE-2026-42792

# crypto-5.5.3.4

The crypto-5.5.3.4 application can be applied independently of other
applications on a full OTP 27 installation.

## Fixed Bugs and Malfunctions

- Fixed crash in crypto:macN/5 when supplied `MacLength` was greater than
  length of what the underlying hash returned.

  Own Id: OTP-20239
  Related Id(s): PR-11239

- Fix cipher key buffer overread for `chacha20_poly1305`.

  Own Id: OTP-20244
  Related Id(s): PR-11337

> #### Full runtime dependencies of crypto-5.5.3.4
>
> erts-9.0, kernel-5.3, stdlib-3.9

# diameter-2.4.1.3

The diameter-2.4.1.3 application can be applied independently of other
applications on a full OTP 27 installation.

## Fixed Bugs and Malfunctions

- Fix infinite loop in diameter_dist:route_session/2 when avp other than
  `Session-Id` has zero length.

  Own Id: OTP-20242
  Related Id(s): PR-11331

- Fix crash in diameter_dist:route_session/2 when `Session-Id` (code: 263) avp
  has zero length.

  Own Id: OTP-20243
  Related Id(s): PR-11333

> #### Full runtime dependencies of diameter-2.4.1.3
>
> erts-10.0, kernel-3.2, ssl-9.0, stdlib-5.0

# erts-15.2.7.11

The erts-15.2.7.11 application can be applied independently of other
applications on a full OTP 27 installation.

## Fixed Bugs and Malfunctions

- Mitigated a denial of service attack in epmd.

  Thanks to Ryan Moore for finding and responsibly disclosing this vulnerability
  to the Erlang/OTP project.

  Own Id: OTP-20136
  Related Id(s): PR-11386, CVE-2026-42792

  *** POTENTIAL INCOMPATIBILITY ***

- Fixed heap corruption when an invalidly encoded tuple with an arity of 2^31 or
  larger is decoded from Erlang's External Term Format (binary_to_term).

  Own Id: OTP-20214
  Related Id(s): PR-11297, CVE-2026-55737

- When send_timeout is set and send_timeout_close is set to true, a 'tcp_closed'
  message is expected when the timeout occurs, but that (message) was not
  delivered. This has now been fixed.

  Own Id: OTP-20257
  Related Id(s): GH-11319

- A crafted External Term Format (ETF) payload could crash the runtime system.

  Thanks to Paul Guyot for finding and responsibly disclosing this vulnerability
  to the Erlang/OTP project.

  Own Id: OTP-20259
  Related Id(s): PR-11386, CVE-2026-54890

> #### Full runtime dependencies of erts-15.2.7.11
>
> kernel-9.0, sasl-3.3, stdlib-4.1

# megaco-4.7.2.2

The megaco-4.7.2.2 application can be applied independently of other
applications on a full OTP 27 installation.

## Fixed Bugs and Malfunctions

- Fixed a buffer overflow in the megaco flex scanner C driver. A property parm
  name exceeding 452 bytes in a text-encoded H.248 message could overflow a
  fixed-size error buffer, crashing the VM. The sprintf calls have been replaced
  with bounded snprintf.

  Own Id: OTP-20237
  Related Id(s): GH-SA-7xgh-gmgf-q2g7, PR-11323

> #### Full runtime dependencies of megaco-4.7.2.2
>
> asn1-3.0, debugger-4.0, erts-12.0, et-1.5, kernel-8.0, runtime_tools-1.8.14,
> stdlib-2.5

# public_key-1.17.1.5

The public_key-1.17.1.5 application can be applied independently of other
applications on a full OTP 27 installation.

## Fixed Bugs and Malfunctions

- A certificate chain with crafted policyMappings extensions could cause
  exponential memory consumption during path validation, exploitable via TLS
  handshake. Chains exceeding a node-count cap are now rejected with {bad_cert,
  policy_tree_exceeded}.

  Own Id: OTP-20251
  Related Id(s): GH-SA-622p-qfh6-c352, PR-11372

> #### Full runtime dependencies of public_key-1.17.1.5
>
> asn1-5.0, crypto-5.0, erts-13.0, kernel-8.0, stdlib-4.0

# ssh-5.2.11.10

The ssh-5.2.11.10 application can be applied independently of other applications
on a full OTP 27 installation.

## Fixed Bugs and Malfunctions

- DH key exchange now enforces strict bounds (1 < e/f < p-1, 1 < K < p-1) on all
  paths, matching OpenSSH and Go. No interop impact.

  Own Id: OTP-20229
  Related Id(s): PR-11303

- Validate DH group parameters (P, G) received from the server during DH-GEX key
  exchange. The client now rejects groups where P is smaller than 2048 bits or G
  is not in the range (1, P-1). The default minimum in dh_gex_limits has been
  raised to 2048 on both client and server.

  Own Id: OTP-20258
  Related Id(s): ERIERL-1341, PR-11369

> #### Full runtime dependencies of ssh-5.2.11.10
>
> crypto-5.0, erts-14.0, kernel-9.0, public_key-1.6.1, runtime_tools-1.15.1,
> stdlib-5.0, stdlib-6.0

# ssl-11.2.12.11

Note! The ssl-11.2.12.11 application _cannot_ be applied independently of other
applications on an arbitrary OTP 27 installation.

       On a full OTP 27 installation, also the following runtime
       dependency has to be satisfied:
       -- public_key-1.17.1.3 (first satisfied in OTP 27.3.4.12)

## Fixed Bugs and Malfunctions

- Add pre TLS-1.3 client side validation of servers algorithm selection being
  part of clients offered algorithms, preventing in worst case MITM
  circumventing validation of server certificate tricking the client to trust
  the malicious MITM as it was a valid server. Note this check is already
  performed for TLS-1.3 clients.

  Own Id: OTP-20240
  Related Id(s): PR-11336, CVE-2026-55953

- Prevent invalid cert chains to create cycles in chain building code used to
  handle chains that could be unordered or contain extraneous certs. This avoids
  a DoS attack possibility.

  Own Id: OTP-20245
  Related Id(s): PR-11343, CVE-2026-58227

- Clarify that rsa_psk and anonymous key exchange algorithms are considered
  legacy. Also harden rsa_psk in same way as normal rsa key exchange.

  Own Id: OTP-20248
  Related Id(s): PR-11341

- Harden SSL application to conform with best practice and RFC's. This will
  mostly improve error messages and conserve memory usage.

  Own Id: OTP-20250
  Related Id(s): PR-27944

- A certificate chain with crafted policyMappings extensions could cause
  exponential memory consumption during path validation, exploitable via TLS
  handshake. Chains exceeding a node-count cap are now rejected with {bad_cert,
  policy_tree_exceeded}.

  Own Id: OTP-20251
  Related Id(s): GH-SA-622p-qfh6-c352, PR-11372

> #### Full runtime dependencies of ssl-11.2.12.11
>
> crypto-5.1, erts-15.0, inets-5.10.7, kernel-9.0, public_key-1.17.1.3,
> runtime_tools-1.15.1, stdlib-6.0

# stdlib-6.2.2.4

The stdlib-6.2.2.4 application can be applied independently of other
applications on a full OTP 27 installation.

## Fixed Bugs and Malfunctions

- Fixed a bug where zip:unzip/1,2 and zip:extract/1,2 were vulnerable to a
  relative path traversal attack. A crafted zip archive containing entry names
  such as ../x/y could have caused files to be written outside the intended
  extraction directory.

  Thanks to Jonatan Männchen and Zhang Delong for finding and responsibly
  disclosing this vulnerability to the Erlang/OTP project.

  Own Id: OTP-20143
  Related Id(s): PR-11386, CVE-2026-47078

> #### Full runtime dependencies of stdlib-6.2.2.4
>
> compiler-5.0, crypto-4.5, erts-15.0, kernel-10.0, sasl-3.0

# Thanks to

Jonatan Männchen



More information about the erlang-announce mailing list