Bug 34067 - erlang new security issue CVE-2025-26618
Summary: erlang new security issue CVE-2025-26618
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2025-03-05 10:28 CET by Nicolas Salguero
Modified: 2025-03-06 18:57 CET (History)
3 users (show)

See Also:
Source RPM: erlang-24.3.4.15-1.mga9.src.rpm
CVE: CVE-2025-26618
Status comment:


Attachments
test file to compile (129 bytes, text/x-matlab)
2025-03-06 14:10 CET, Herman Viaene
Details

Description Nicolas Salguero 2025-03-05 10:28:51 CET
Ubuntu has issued an advisory on March 3:
https://ubuntu.com/security/notices/USN-7313-1
Nicolas Salguero 2025-03-05 10:30:54 CET

Source RPM: (none) => erlang-24.3.4.15-1.mga10.src.rpm, erlang-24.3.4.15-1.mga9.src.rpm
Status comment: (none) => Patch available from Ubuntu
CVE: (none) => CVE-2025-26618
Whiteboard: (none) => MGA9TOO

Nicolas Salguero 2025-03-05 17:08:53 CET

Assignee: bugsquad => nicolas.salguero

Comment 1 Nicolas Salguero 2025-03-06 09:44:51 CET
Suggested advisory:
========================

The updated packages fix a security vulnerability:

SSH SFTP packet size not verified properly in Erlang OTP. (CVE-2025-26618)

References:
https://ubuntu.com/security/notices/USN-7313-1
========================

Updated packages in core/updates_testing:
========================
erlang-24.3.4.15-1.1.mga9
erlang-asn1-24.3.4.15-1.1.mga9
erlang-common_test-24.3.4.15-1.1.mga9
erlang-compiler-24.3.4.15-1.1.mga9
erlang-crypto-24.3.4.15-1.1.mga9
erlang-debugger-24.3.4.15-1.1.mga9
erlang-dialyzer-24.3.4.15-1.1.mga9
erlang-diameter-24.3.4.15-1.1.mga9
erlang-doc-24.3.4.15-1.1.mga9
erlang-edoc-24.3.4.15-1.1.mga9
erlang-eldap-24.3.4.15-1.1.mga9
erlang-erl_docgen-24.3.4.15-1.1.mga9
erlang-erl_interface-24.3.4.15-1.1.mga9
erlang-erts-24.3.4.15-1.1.mga9
erlang-et-24.3.4.15-1.1.mga9
erlang-eunit-24.3.4.15-1.1.mga9
erlang-examples-24.3.4.15-1.1.mga9
erlang-ftp-24.3.4.15-1.1.mga9
erlang-inets-24.3.4.15-1.1.mga9
erlang-jinterface-24.3.4.15-1.1.mga9
erlang-kernel-24.3.4.15-1.1.mga9
erlang-megaco-24.3.4.15-1.1.mga9
erlang-mnesia-24.3.4.15-1.1.mga9
erlang-observer-24.3.4.15-1.1.mga9
erlang-odbc-24.3.4.15-1.1.mga9
erlang-os_mon-24.3.4.15-1.1.mga9
erlang-parsetools-24.3.4.15-1.1.mga9
erlang-public_key-24.3.4.15-1.1.mga9
erlang-reltool-24.3.4.15-1.1.mga9
erlang-runtime_tools-24.3.4.15-1.1.mga9
erlang-sasl-24.3.4.15-1.1.mga9
erlang-snmp-24.3.4.15-1.1.mga9
erlang-ssh-24.3.4.15-1.1.mga9
erlang-ssl-24.3.4.15-1.1.mga9
erlang-stdlib-24.3.4.15-1.1.mga9
erlang-syntax_tools-24.3.4.15-1.1.mga9
erlang-tftp-24.3.4.15-1.1.mga9
erlang-tools-24.3.4.15-1.1.mga9
erlang-wx-24.3.4.15-1.1.mga9
erlang-xmerl-24.3.4.15-1.1.mga9

from SRPM:
erlang-24.3.4.15-1.1.mga9.src.rpm

Version: Cauldron => 9
Assignee: nicolas.salguero => qa-bugs
Source RPM: erlang-24.3.4.15-1.mga10.src.rpm, erlang-24.3.4.15-1.mga9.src.rpm => erlang-24.3.4.15-1.mga9.src.rpm
Whiteboard: MGA9TOO => (none)
Status comment: Patch available from Ubuntu => (none)

Comment 2 Herman Viaene 2025-03-06 14:09:53 CET
MGA9-64 Plasma Wayland on Compaq H000SB.
No installation issues.
Followed lead from TJ in bug 31190 (attaching test file here).
$ erlc helloworld.erl 2>&1
$ erl -noshell -s helloworld start -s init stop

Hello, world!

Good enough.

CC: (none) => herman.viaene
Whiteboard: (none) => MGA9-64-OK

Comment 3 Herman Viaene 2025-03-06 14:10:49 CET
Created attachment 14888 [details]
test file to compile
Comment 4 Thomas Andrews 2025-03-06 16:12:12 CET
Validating.

CC: (none) => andrewsfarm, sysadmin-bugs
Keywords: (none) => validated_update

katnatek 2025-03-06 17:10:50 CET

Keywords: (none) => advisory

Comment 5 Mageia Robot 2025-03-06 18:57:46 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2025-0088.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.