chore(deps): update dependency erlang to v29.1.1 #233

Open
renovate wants to merge 1 commit from renovate/erlang-29.x into main
Collaborator

This PR contains the following updates:

Package Update Change
erlang minor 29.0.1 → 29.1.1

Release Notes

erlang/otp (erlang)

v29.1.1: OTP 29.1.1

Compare Source

Patch Package:           OTP 29.1.1
Git Tag:                 OTP-29.1.1
Date:                    2026-09-22
Trouble Report Id:       OTP-20272, OTP-20287, OTP-20355, OTP-20371,
                         OTP-20386, OTP-20388, OTP-20390, OTP-20393
Seq num:                 CVE-2026-65634, CVE-2026-68956,
                         CVE-2026-89422, ERIERL-1355, ERIERL-1363,
                         GH-11586, GH-11619, GH-SA-qhcm-px9c-rvfh,
                         PR-11523, PR-11559, PR-11616, PR-11630,
                         PR-11638, PR-11641, PR-11651, PR-11655
System:                  OTP
Release:                 29
Application:             asn1-5.5.2, compiler-10.0.6,
                         public_key-1.21.7, ssh-6.0.6, ssl-11.7.7
Predecessor:             OTP 29.1

Check out the git tag OTP-29.1.1, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.

POTENTIAL INCOMPATIBILITIES

  • Fixed a vulnerability where the max_channels daemon option was not enforced for session channels without an active subsystem, allowing a remote authenticated user to open an infinite number of channels and exhaust server resources despite the configured limit.

    The default value of the max_channels daemon option has been changed from infinity to 256. Deployments requiring more than 256 simultaneous channels per connection can restore the previous behavior by setting {max_channels, infinity}.

    The default value of the max_sessions daemon option has been changed from infinity to 1024. Deployments requiring more concurrent SSH connections can restore the previous behavior by setting {max_sessions, infinity}.

    Own Id: OTP-20287
    Application(s): ssh
    Related Id(s): GH-SA-qhcm-px9c-rvfh, PR-11523, CVE-2026-68956

asn1-5.5.2

The asn1-5.5.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed a denial-of-service attack in asn1, where abnormally large OID components (arcs) could cause resource exhaustion.

    Own Id: OTP-20272
    Related Id(s): PR-11655, CVE-2026-65634

  • The JER backend will no longer break certain values (true, false, null) when they are typed as ENUMERATED, they will now be encoded as strings as required by the standard.

    Own Id: OTP-20355
    Related Id(s): ERIERL-1355, PR-11559

Full runtime dependencies of asn1-5.5.2

erts-14.0, kernel-9.0, stdlib-5.0

compiler-10.0.6

The compiler-10.0.6 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Certain uses of funs could crash the compiler. For example:

    f() ->
        F = fun Fn(0) -> 0; Fn(N) -> Fn(N - 1) end,
        [F(X) || X <- [1, 2]].
    

    This has been corrected.

    Own Id: OTP-20386
    Related Id(s): GH-11619, PR-11638

Full runtime dependencies of compiler-10.0.6

crypto-5.1, erts-13.0, kernel-8.4, stdlib-8.0

public_key-1.21.7

The public_key-1.21.7 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Handle that policy qualifiers are optional.

    Own Id: OTP-20393
    Related Id(s): PR-11630

Full runtime dependencies of public_key-1.21.7

asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0

ssh-6.0.6

The ssh-6.0.6 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed a vulnerability where the max_channels daemon option was not enforced for session channels without an active subsystem, allowing a remote authenticated user to open an infinite number of channels and exhaust server resources despite the configured limit.

    The default value of the max_channels daemon option has been changed from infinity to 256. Deployments requiring more than 256 simultaneous channels per connection can restore the previous behavior by setting {max_channels, infinity}.

    The default value of the max_sessions daemon option has been changed from infinity to 1024. Deployments requiring more concurrent SSH connections can restore the previous behavior by setting {max_sessions, infinity}.

    Own Id: OTP-20287
    Related Id(s): GH-SA-qhcm-px9c-rvfh, PR-11523, CVE-2026-68956

    *** POTENTIAL INCOMPATIBILITY ***

  • The SSH daemon no longer rejects a subsystem request that is preceded by env or pty-req request on the same channel.

    Own Id: OTP-20371
    Related Id(s): ERIERL-1363, GH-11586, PR-11616

Full runtime dependencies of ssh-6.0.6

crypto-5.7, erts-14.0, kernel-10.3, public_key-1.6.1, runtime_tools-1.15.1, stdlib-8.0

ssl-11.7.7

Note! The ssl-11.7.7 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.

   On a full OTP 29 installation, also the following runtime
   dependency has to be satisfied:
   -- public_key-1.21.1 (first satisfied in OTP 29.0.1)

Fixed Bugs and Malfunctions

  • Reject unsolicited TLS-1.3 pre_shared_key in client.

    Own Id: OTP-20388
    Related Id(s): PR-11641, CVE-2026-89422

  • Security and robustness hardening returning RFC mandated alert reasons, narrowing/correcting length checks.

    Correct signature algorithm handling that slightly mixed up signature algorithms and signature algorithms cert in TLS-1.2.

    Add missing TLS-1.3 Brainpool groups support. (Not relevant in 27 patch)

    Enhanced/corrected documentation and spec errors/deviations.

    Own Id: OTP-20390
    Related Id(s): PR-11651

Full runtime dependencies of ssl-11.7.7

crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public_key-1.21.1, runtime_tools-1.15.1, stdlib-7.0

Thanks to

Alan Duffield

v29.1: OTP 29.1

Compare Source

Patch Package:           OTP 29.1
Git Tag:                 OTP-29.1
Date:                    2026-09-16
Trouble Report Id:       OTP-19631, OTP-20118, OTP-20131, OTP-20145,
                         OTP-20152, OTP-20158, OTP-20169, OTP-20175,
                         OTP-20177, OTP-20180, OTP-20187, OTP-20188,
                         OTP-20189, OTP-20209, OTP-20211, OTP-20213,
                         OTP-20218, OTP-20228, OTP-20235, OTP-20236,
                         OTP-20238, OTP-20246, OTP-20249, OTP-20254,
                         OTP-20255, OTP-20256, OTP-20262, OTP-20265,
                         OTP-20267, OTP-20276, OTP-20277, OTP-20280,
                         OTP-20290, OTP-20291, OTP-20292, OTP-20293,
                         OTP-20295, OTP-20297, OTP-20298, OTP-20303,
                         OTP-20304, OTP-20305, OTP-20309, OTP-20316,
                         OTP-20317, OTP-20318, OTP-20320, OTP-20322,
                         OTP-20326, OTP-20327, OTP-20328, OTP-20331,
                         OTP-20335, OTP-20338, OTP-20339, OTP-20352,
                         OTP-20354, OTP-20356, OTP-20358, OTP-20362,
                         OTP-20364, OTP-20365, OTP-20367, OTP-20373,
                         OTP-20374
Seq num:                 ERIERL-1356, GH-10879, GH-10968, GH-11093,
                         GH-11119, GH-11155, GH-11248, GH-11308,
                         GH-11338, GH-11344, GH-11349, GH-11351,
                         GH-11352, GH-11360, GH-11366, GH-11367,
                         GH-11397, GH-11398, GH-11401, GH-11406,
                         GH-11413, GH-11414, GH-11423, GH-11472,
                         GH-11534, GH-4417, GH-7862, GH-9302,
                         OTP-20102, PR-10297, PR-11074, PR-11096,
                         PR-11097, PR-11115, PR-11128, PR-11129,
                         PR-11130, PR-11133, PR-11137, PR-11144,
                         PR-11159, PR-11165, PR-11167, PR-11170,
                         PR-11196, PR-11203, PR-11216, PR-11226,
                         PR-11249, PR-11260, PR-11274, PR-11284,
                         PR-11300, PR-11313, PR-11316, PR-11324,
                         PR-11335, PR-11345, PR-11356, PR-11359,
                         PR-11361, PR-11363, PR-11375, PR-11376,
                         PR-11378, PR-11379, PR-11388, PR-11390,
                         PR-11391, PR-11396, PR-11410, PR-11422,
                         PR-11424, PR-11426, PR-11438, PR-11440,
                         PR-11442, PR-11444, PR-11446, PR-11447,
                         PR-11460, PR-11466, PR-11477, PR-11501,
                         PR-11505, PR-11507, PR-11530, PR-11552,
                         PR-11556, PR-11563, PR-11566, PR-11567,
                         PR-11570, PR-11574, PR-11600
System:                  OTP
Release:                 29
Application:             asn1-5.5.1, common_test-1.31.2,
                         compiler-10.0.5, crypto-5.10, dialyzer-6.0.3,
                         erts-17.1, inets-9.8, kernel-11.0.4,
                         mnesia-4.27, odbc-2.17.1, public_key-1.21.6,
                         runtime_tools-2.5, ssl-11.7.6, stdlib-8.1,
                         syntax_tools-4.1.1, tools-4.2.3, wx-2.7
Predecessor:             OTP 29.0.6

Check out the git tag OTP-29.1, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.

POTENTIAL INCOMPATIBILITIES

  • When beam_lib returns an error tuple, the filename in the information tuple is now a list of characters instead of an atom.

    Example:

    1> beam_lib:chunks(code:which(lists), ["nope"]).
    {error,beam_lib,
           {missing_chunk,".../git/otp/lib/stdlib/ebin/lists.beam",
                          "nope"}}
    

    The reason for this change is that a long file name is not guaranteed to fit in an atom. Applications or tools that do deep inspection of the beam_lib errors (not recommended) will need to be updated.

    Own Id: OTP-20118
    Application(s): stdlib
    Related Id(s): PR-11167

OTP-29.1

Improvements and New Features

asn1-5.5.1

The asn1-5.5.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • The modern representation of BITSTRINGs is now always supported for encoding, regardless of any legacy options given. The JER backend would not support the modern representation when any legacy option was given.

    Own Id: OTP-20145
    Related Id(s): PR-11097

  • The make clean command did not remove all generated .erl files.

    Own Id: OTP-20295
    Related Id(s): PR-11375

Full runtime dependencies of asn1-5.5.1

erts-14.0, kernel-9.0, stdlib-5.0

common_test-1.31.2

The common_test-1.31.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • The internal cte_track event handler now correctly displays the suite name for suites without an init_per_suite/1 callback.

    Own Id: OTP-20316
    Related Id(s): PR-11501

Full runtime dependencies of common_test-1.31.2

compiler-10.0, crypto-4.5, debugger-4.1, erts-7.0, ftp-1.0, inets-6.0, kernel-11.0, observer-2.1, runtime_tools-1.8.16, sasl-2.5, snmp-5.1.2, ssh-4.0, stdlib-8.0, syntax_tools-1.7, tools-3.2, xmerl-1.3.8

compiler-10.0.5

The compiler-10.0.5 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed a native record crash in the sys_core_fold compiler pass.

    Own Id: OTP-20254
    Related Id(s): GH-11351, PR-11359

  • The compiler could crash when compiling a map comprehension.

    Own Id: OTP-20255
    Related Id(s): GH-11352, PR-11363

  • Fixed a crash when the key pattern in a map comprehension was a bitstring.

    Own Id: OTP-20262
    Related Id(s): GH-11367, PR-11379

  • Fixed an issue that could crash the compiler when compiling comprehensions with the compr_assign feature enabled.

    Own Id: OTP-20267
    Related Id(s): GH-11366, PR-11390

  • Code that called erlang:0() inside a fun could crash the compiler.

    Own Id: OTP-20280
    Related Id(s): GH-11414, PR-11424

  • Fixed an internal error when lists:keyfind/3 is called with an argument that exceeds system limits.

    Own Id: OTP-20291
    Related Id(s): GH-11413, PR-11444

  • An incorrect useless_building warning has been eliminated.

    Own Id: OTP-20304
    Related Id(s): GH-11472, PR-11477

  • In rare circumstances, the type analysis pass of the compiler could run for many minutes.

    Own Id: OTP-20365
    Related Id(s): GH-11534, PR-11566

Full runtime dependencies of compiler-10.0.5

crypto-5.1, erts-13.0, kernel-8.4, stdlib-8.0

crypto-5.10

The crypto-5.10 application can be applied independently of other applications on a full OTP 29 installation.

Improvements and New Features

  • The documentation of the crypto module now contains runnable examples for most functions. The examples are verified by the crypto test suite, so they always match actual behavior.

    Own Id: OTP-20373
    Related Id(s): PR-11170

Full runtime dependencies of crypto-5.10

erts-9.0, kernel-6.0, stdlib-3.9

dialyzer-6.0.3

The dialyzer-6.0.3 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed Dialyzer crash when overriding built-in types.

    Own Id: OTP-19631
    Related Id(s): GH-11093, PR-11096

  • Typer crashed when multiple functions were written in the same line. For example:

    -module(m).
    f() -> ok. g() -> ok.
    

    Own Id: OTP-20297
    Related Id(s): PR-11466

Full runtime dependencies of dialyzer-6.0.3

compiler-10.0, erts-12.0, kernel-8.0, stdlib-5.0, syntax_tools-2.0

erts-17.1

The erts-17.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed bug in ets:member/2 for set, bag and duplicate_bag. The bug could (maybe) lead to ets:member spuriously returning false for a value which is actually a member for a table that faces high insert load.

    Own Id: OTP-20152
    Related Id(s): PR-11115

  • Fixed crashing bug caused by race between timer creating process and suspending receiver of the timer. Only seen to cause crash one time by extremely provoking test case. Bug exists only since OTP 29.0.

    Own Id: OTP-20175
    Related Id(s): PR-11196

  • Fixed bug in enif_realloc_binary when called with a read-only binary. Instead of returning false at out-of-memory failure, it returned true and did nothing.

    Own Id: OTP-20187
    Related Id(s): PR-11133

  • Fixed alternate signal stack sizing on musl (Alpine) running on CPUs whose Linux kernel reports large signal frames (AVX-512/AMX). It caused emulator to abort during startup with "Failed to set alternate signal stack".

    Own Id: OTP-20213
    Related Id(s): GH-11248, PR-11249

  • For socket:recvmmsg/6, the buffer length was not handled correctly when the OS network stack truncated the received message, so garbage data with incorrect length could be delivered to the calling process. This bug has been corrected.

    Own Id: OTP-20246
    Related Id(s): PR-11335

  • binary_to_term/1 will now reject an external native record with duplicated fields.

    Own Id: OTP-20276
    Related Id(s): GH-11398, PR-11410

  • Fixed a crash upon starting the emulator on systems with a very large minimum signal stack size.

    Own Id: OTP-20292
    Related Id(s): GH-11349, PR-11376

  • Fixed lock order violation during crash dump due to export table exhaustion. Only problem for debug emulator.

    Own Id: OTP-20305
    Related Id(s): PR-11460

  • Fixed rounding errors when converting large integers to floating point numbers, explicitly with float/1 or implicitly in arithmetic such as 1.0 * N. Integers with absolute values larger than 64 bits that could not be represented exactly as a float could be rounded to the second nearest float instead of the nearest. For example, float(428654966685883400000) returned 4.2865496668588343e20 instead of the correct 4.286549666858834e20, which is what binary_to_float/1 returns for the same number.

    Own Id: OTP-20317
    Related Id(s): PR-11391

  • An error check in prim_inet has been fixed. This manifested itself as file:sendfile/* sometimes crashing instead of returning an error when the remote end closes the socket during initialization.

    Own Id: OTP-20356
    Related Id(s): PR-11438

Improvements and New Features

  • Fairness of code permission locks have been improved to avoid long latencies for code loading and trace operations.

    Own Id: OTP-20188
    Related Id(s): PR-11144

  • The BIFs that convert strings to integers (for example binary_to_integer/1) are now much faster for huge input strings. On a modern computer, even a string with more than a million decimal digits should finish in less than a second.

    The div and rem operators are now also much faster for large operands.

    Own Id: OTP-20209
    Related Id(s): PR-11074, PR-11324

  • Arithmetic operations on large integers will now increase the reduction count for the process, causing context switches to occur more frequently when doing arithmetic on large integers.

    Own Id: OTP-20211
    Related Id(s): PR-11274

Full runtime dependencies of erts-17.1

kernel-9.0, sasl-3.3, stdlib-4.1

inets-9.8

The inets-9.8 application can be applied independently of other applications on a full OTP 29 installation.

Improvements and New Features

  • OPTIONS is now accepted for HTTP/1.x requests and routed through the normal module pipeline like other standard methods. Requests that no module handles still receive a 501 (Not Implemented) response, so behavior is unchanged for deployments that do not add explicit OPTIONS handling.

    Own Id: OTP-20249
    Related Id(s): GH-11119, PR-11316

Full runtime dependencies of inets-9.8

erts-14.0, kernel-9.0, mnesia-4.12, public_key-1.13, runtime_tools-1.8.14, ssl-9.0, stdlib-5.0, stdlib-6.0

kernel-11.0.4

The kernel-11.0.4 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed incorrect TOS format when using gen_udp with the socket backend.

    Own Id: OTP-20131
    Related Id(s): GH-10968, OTP-20102

  • Decoding of names in inet_res has been tightened to not allow names longer than 255 octets, as according to RFC 1035.

    Decoding has also been made more strict by only allowing compression pointers to lower positions in the message.

    A few bugs when decoding malformed truncated DNS messages have also been fixed, as well as handling broken UTF-8 content in NAPTR RR:s regular expressions field.

    Own Id: OTP-20228
    Related Id(s): PR-11300

  • When using the socket backend in gen_tcp, the default value for the read_ahead option was incorrect and has been corrected, according the documentation, to be true.

    Own Id: OTP-20238
    Related Id(s): PR-11284

  • A field in net_kernel's internal state was not cleaned up in some cases for failed connections could cause the state to grow indefinitely over time. This has now been fixed.

    Own Id: OTP-20265
    Related Id(s): GH-11308, PR-11388

  • Fixed pg:which_groups/1 to not include empty groups where all members have leaved. Bug existed since OTP 29.0.

    Own Id: OTP-20303
    Related Id(s): GH-11360, PR-11361

Full runtime dependencies of kernel-11.0.4

crypto-5.8, erts-17.0, sasl-3.0, stdlib-8.0

mnesia-4.27

The mnesia-4.27 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed mnesia:force_load_table/1 getting stuck when the remote node becomes unreachable during table loading. When a network loader is aborted due to sender node going down and a user has forced a table load, we now retry loading from disc instead. Additionally, for disc_only_copies tables, the process actually loading the table is the dets server process, not the mnesia loader, so it would not receive the abort notification and would hang indefinitely. Now it correctly receives the notification and aborts table loading.

    Own Id: OTP-20256
    Related Id(s): GH-11344, PR-11426

  • Fixed incorrect results from mnesia:select_reverse/2,3 on ordered_set tables inside a transaction that had already written to or deleted from the same table. Deleted records could reappear, updated records could appear twice, and the descending order was not preserved.

    Own Id: OTP-20364
    Related Id(s): PR-11563

Improvements and New Features

  • The documentation of the mnesia module now contains runnable examples for most functions. The examples are verified by the mnesia test suite, so they always match actual behavior.

    Own Id: OTP-20374
    Related Id(s): PR-11216

Full runtime dependencies of mnesia-4.27

erts-9.0, kernel-5.3, stdlib-5.0

odbc-2.17.1

The odbc-2.17.1 application can be applied independently of other applications on a full OTP 29 installation.

Improvements and New Features

  • Added the max_long_column_size option to limit buffer allocation size preventing memory exhaustion.

    Own Id: OTP-20328
    Related Id(s): GH-9302, PR-10297

Full runtime dependencies of odbc-2.17.1

erts-6.0, kernel-3.0, stdlib-2.0

public_key-1.21.6

The public_key-1.21.6 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Added missing no_cacerts_found clauses so that the intended {failed_load_cacerts, no_cacerts_found} error is raised and formatted properly.

    Own Id: OTP-20318
    Related Id(s): PR-11378

  • Align moduli and pubkey_moduli.hrl to state on OTP-28 and newer.

    Own Id: OTP-20367
    Related Id(s): PR-11574

Improvements and New Features

  • Worked around domain component using wrong ASN-1 PrintableString encoding instead of IA5String encoding.

    Own Id: OTP-20338
    Related Id(s): GH-10879, PR-11226

  • ASN.1 files are now compiled sequentially to guarantee reproducible builds.

    Own Id: OTP-20362
    Related Id(s): GH-4417, PR-11396

Full runtime dependencies of public_key-1.21.6

asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0

runtime_tools-2.5

The runtime_tools-2.5 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed bug if a process that called dbg:session/2 exits before dbg:session_destroy/1 is called. An error report was logged and any trace messages lost and not delivered.

    Own Id: OTP-20218
    Related Id(s): PR-11260

Improvements and New Features

Full runtime dependencies of runtime_tools-2.5

erts-16.0, kernel-10.0, mnesia-4.12, stdlib-6.0

ssl-11.7.6

Note! The ssl-11.7.6 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.

   On a full OTP 29 installation, also the following runtime
   dependency has to be satisfied:
   -- public_key-1.21.1 (first satisfied in OTP 29.0.1)

Fixed Bugs and Malfunctions

  • Undecodable certificate_authorities names are now skipped, as they are just a hint.

    Own Id: OTP-20327
    Related Id(s): GH-11338, PR-11356

  • Corrected generated keylog information generated from the keylog_hs option in the corner case that it was invoked after the client had reached its connection state, but the server closed the connection before it reached its connection state.

    Own Id: OTP-20358
    Related Id(s): ERIERL-1356, PR-11570

Improvements and New Features

  • Added TLS-1.3 selected_group to ssl:connection_information/2.

    Own Id: OTP-20326
    Related Id(s): PR-11440

  • The ECDHE-PSK Chacha20-Poly1305 cipher suites are now supported. This is relevant for TLS-1.2 (and lower).

    Own Id: OTP-20331
    Related Id(s): PR-11345

Full runtime dependencies of ssl-11.7.6

crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public_key-1.21.1, runtime_tools-1.15.1, stdlib-7.0

stdlib-8.1

The stdlib-8.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • When beam_lib returns an error tuple, the filename in the information tuple is now a list of characters instead of an atom.

    Example:

    1> beam_lib:chunks(code:which(lists), ["nope"]).
    {error,beam_lib,
           {missing_chunk,".../git/otp/lib/stdlib/ebin/lists.beam",
                          "nope"}}
    

    The reason for this change is that a long file name is not guaranteed to fit in an atom. Applications or tools that do deep inspection of the beam_lib errors (not recommended) will need to be updated.

    Own Id: OTP-20118
    Related Id(s): PR-11167

    *** POTENTIAL INCOMPATIBILITY ***

  • The default seed in the rand module has been improved to spread out its entropy over all three seed words.

    This avoids identical first random numbers from two successive seeds on machines with low system time resolution.

    Own Id: OTP-20158
    Related Id(s): PR-11165

  • Fixed unicode:characters_to_binary/2 to handle incomplete utf-32 sequences without crashing.

    Also fixed a performance regression in unicode:characters_to_nfkd_list/1.

    Own Id: OTP-20169
    Related Id(s): PR-11130

  • The array module has been improved. array:slice/3 now raises badarg for negative lengths.

    The performance of array:mapfoldl/3 and array:sparse_mapfoldl/3 has been improved.

    The documentation has been clarified regarding array growth/shrink behavior and how concat/1,2 handles mixed arrays.

    Own Id: OTP-20177
    Related Id(s): PR-11159

  • Added more checks in the linter for badly formed {Name,Arity} attributes

    Own Id: OTP-20277
    Related Id(s): GH-11397, PR-11422

  • Fixed return value of zip:zip_get/2. When a file was extracted to a directory, the function returned a map instead of a file name.

    Own Id: OTP-20298
    Related Id(s): PR-11313

  • When compr_assign is enabled, the linter will correctly check for unbounded variables after block expressions in comprehensions.

    Own Id: OTP-20309
    Related Id(s): GH-11406, PR-11567

  • When compiling a module with a triple-quoted string with escape sequences and a chunk boundary happened to fall just after an escape character, that character was not passed to the reentrancy continuation, so the scanner interpreted the following characters as not an escape sequence.

    This bug has now been fixed.

    Own Id: OTP-20320
    Related Id(s): GH-11423, PR-11505

  • Fixed some errors in examples in the documentation for the string and uri_string modules.

    Own Id: OTP-20322
    Related Id(s): PR-11446

  • Linter will emit better error messages when a behaviour attribute has a bad module name.

    Own Id: OTP-20354
    Related Id(s): GH-11401, PR-11552

Improvements and New Features

  • uri_string:parse/1 now reports the actual offending character in error tuples instead of reporting a misleading cascade-failure position.

    Previously, when parsing a URI containing an invalid character (such as | or non-ASCII characters like ö), the error tuple would point to the : character — the position where the parser's final backtracking attempt failed — rather than the character that actually violated the URI grammar. For example, uri_string:parse("http://localhost/A|B") returned {error,invalid_uri,":"} instead of the more helpful {error,invalid_uri,"|"}

    Own Id: OTP-20235
    Related Id(s): GH-7862, PR-11129

  • Fixed a guard precedence bug in uri_string:compose_query/2 that caused inconsistent error handling depending on the encoding option.

    When compose_query/2 was called with invalid input (e.g. an atom instead of a string) and {encoding, unicode}, it would crash with ** exception error: bad argument instead of returning the expected {error, invalid_input, Term} tuple. The same call with {encoding, utf8} correctly returned the error tuple. Both encoding options now consistently return {error, invalid_input, Term} for invalid input.

    Own Id: OTP-20236
    Related Id(s): PR-11128

Full runtime dependencies of stdlib-8.1

compiler-5.0, crypto-4.5, erts-16.0.3, kernel-11.0, sasl-3.0, syntax_tools-3.2.1

syntax_tools-4.1.1

The syntax_tools-4.1.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed exception when the epp_dodger AST contains macro-named record.

    Own Id: OTP-20180
    Related Id(s): GH-11155, PR-11203

  • Any caller who passed a single syntax tree that was not a form_list (e.g. erl_recomment:recomment_forms(erl_syntax:atom(foo), Cs) or any expression/function tree) would get a hard crash instead of the documented result. This issue has been fixed.

    Own Id: OTP-20290
    Related Id(s): PR-11442

Full runtime dependencies of syntax_tools-4.1.1

compiler-9.0, erts-16.0, kernel-10.3, stdlib-8.0

tools-4.2.3

The tools-4.2.3 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • The tags.erl module is used to generate TAGS files for Emacs. There was a case where single quote items starting in position 0 would crash the scanner. This use case can potentially happen in docstrings, although not too common. This fix makes the scanner to handle such cases instead of crashing.

    Own Id: OTP-20293
    Related Id(s): PR-11447

  • Updated the Emacs skeleton to reflect latest format_status callback handling.

    Own Id: OTP-20339
    Related Id(s): PR-11507

Full runtime dependencies of tools-4.2.3

compiler-8.5, crypto-5.9, erts-15.0, kernel-10.0, public_key-1.21, runtime_tools-2.1, stdlib-6.0

wx-2.7

The wx-2.7 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • A large set of correctness and robustness fixes were applied across the wx application, addressing issues found by static analysis of both the Erlang and C/C++ sources.

    Own Id: OTP-20335
    Related Id(s): PR-11530

Improvements and New Features

  • Removed configure checks that prevented cross compilation of wx. Note that cross compilation is not tested and may require manual configuration.

    Own Id: OTP-20189
    Related Id(s): PR-11137

Full runtime dependencies of wx-2.7

erts-12.0, kernel-8.0, stdlib-5.0

Thanks to

Alois Vitasek, Anton Thomasson, ausimian, Bernhard M. Wiedemann, Cole Christensen, Dmitri Vereshchagin, Dmytro Lytovchenko, Eric Meadows-Jönsson, haoxian, Jianbo He, João Henrique Ferreira de Freitas, Johan Bevemyr, John Downey, Jonatan Männchen, Julian Doherty, kagetora66, k-patrik, Louis Pilfold, Lukasz Samson, Luke Bakken, Maria Scott, Mikael Pettersson, Paul Guyot, Renato Ceolin, ruslandoga, Scott Wiggins, Stanislav Yaglo, Thomas Arts, Thomas Cioppettini, Zeke Dou, zmstone

v29.0.6: OTP 29.0.6

Compare Source

Patch Package:           OTP 29.0.6
Git Tag:                 OTP-29.0.6
Date:                    2026-09-01
Trouble Report Id:       OTP-20135, OTP-20234, OTP-20264, OTP-20268,
                         OTP-20269, OTP-20270, OTP-20271, OTP-20274,
                         OTP-20278, OTP-20279, OTP-20281, OTP-20282,
                         OTP-20284, OTP-20286, OTP-20289, OTP-20296,
                         OTP-20300, OTP-20301, OTP-20302, OTP-20306,
                         OTP-20307, OTP-20308, OTP-20312, OTP-20319,
                         OTP-20321, OTP-20324, OTP-20330, OTP-20333,
                         OTP-20334, OTP-20342, OTP-20343, OTP-20344,
                         OTP-20345, OTP-20346, OTP-20347, OTP-20350,
                         OTP-20351
Seq num:                 CVE-2026-75538, ERIERL-1345, ERIERL-1354,
                         GH-11052, GH-11240, GH-11278, GH-11380,
                         GH-11404, GH-11416, GH-11419, GH-11494,
                         GH-11511, PR-11298, PR-11325, PR-11358,
                         PR-11417, PR-11425, PR-11428, PR-11429,
                         PR-11437, PR-11463, PR-11464, PR-11470,
                         PR-11478, PR-11481, PR-11485, PR-11492,
                         PR-11503, PR-11509, PR-11513, PR-11517,
                         PR-11521, PR-11533, PR-11538, PR-11539,
                         PR-11540, PR-11541, PR-11542, PR-11543,
                         PR-11544, PR-11545, PR-11546, PR-11547,
                         PR-11548, PR-11553, PR-11554
System:                  OTP
Release:                 29
Application:             compiler-10.0.4, crypto-5.9.3, eldap-1.3.1,
                         erl_interface-5.8.2, erts-17.0.6,
                         inets-9.7.2, megaco-4.9.2, mnesia-4.26.2,
                         public_key-1.21.5, snmp-5.20.5, ssh-6.0.5,
                         ssl-11.7.5, stdlib-8.0.4, tools-4.2.2
Predecessor:             OTP 29.0.5

Check out the git tag OTP-29.0.6, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.

compiler-10.0.4

The compiler-10.0.4 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • compiler: Fix bug in beam_types:subtract/2 for bitstrings

    Own Id: OTP-20312
    Related Id(s): GH-11494, PR-11503

Full runtime dependencies of compiler-10.0.4

crypto-5.1, erts-13.0, kernel-8.4, stdlib-8.0

crypto-5.9.3

The crypto-5.9.3 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed type mismatch between ErlNifUInt64 and uint64_t in crypto NIF that caused incompatible-pointer warnings on macOS arm64 when passing DH parameters to OpenSSL.

    Own Id: OTP-20333
    Related Id(s): GH-11511, PR-11513

Full runtime dependencies of crypto-5.9.3

erts-9.0, kernel-6.0, stdlib-3.9

eldap-1.3.1

The eldap-1.3.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • eldap referral URL parsing now rejects a port component longer than 5 digits instead of attempting to convert an arbitrarily large digit string to an integer.

    Own Id: OTP-20345
    Related Id(s): PR-11538 CVE-2026-70409

Full runtime dependencies of eldap-1.3.1

asn1-3.0, erts-6.0, kernel-3.0, ssl-5.3.4, stdlib-3.4

erl_interface-5.8.2

The erl_interface-5.8.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • erl_interface: Fix buffer leak and state corruption on ei_x_buff realloc failure

    Own Id: OTP-20324
    Related Id(s): PR-11492

erts-17.0.6

The erts-17.0.6 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • No-suspend port command signals (i.e. port command signals sent using the erlang:port_command/3 BIF or the erlang:send/3 BIF with the nosuspend option) were not aborted properly in all scenarios which could leave the port queue in a busy state indefinitely. Also asynchronously sent no-suspend command signals (i.e, port command signals sent using the erlang:send/3 BIF with the nosuspend option) could sometimes be delivered even though the port was busy.

    Own Id: OTP-20135
    Related Id(s): GH-11052, PR-11463

  • erts: Fix missing exit_status caused by SIGCHLD race

    Own Id: OTP-20274
    Related Id(s): GH-11278, PR-11298

  • erts: Fix bug in is_in_range instruction for x86 JIT

    Own Id: OTP-20278
    Related Id(s): GH-11419, PR-11429

  • Fixed bug in binary_to_term that could cause emulator crash for specific terms in specific process states (reductions left).

    Own Id: OTP-20281
    Related Id(s): GH-11404, PR-11425

  • erts: Fix crash with term_to_iovec/2 for large binary

    Own Id: OTP-20282
    Related Id(s): PR-11428

  • A distributed priority send larger than 32 KiB to a process alias caused the receiving runtime system to crash.

    Own Id: OTP-20286
    Related Id(s): GH-11416, PR-11417

  • Priority message queue markers were sometimes installed in the message queue even when no priority messages could be received. As a result, the two markers had to be traversed unnecessarily when scanning the message queue, introducing a small but avoidable overhead.

    Own Id: OTP-20300
    Related Id(s): PR-11485

  • A monitor of time_offset co-created with a process alias (monitor(time_offset, clock_service, [{alias, UnaliasOpt}])) either crashed the runtime system or did not work. This bug was introduced in OTP 25.0.

    Own Id: OTP-20319
    Related Id(s): PR-11509

  • A process alias was erroneously created when a remote spawn_request() operation with a {monitor, [{alias, explicit_unalias}]} option failed with noconnection reason.

    Own Id: OTP-20330
    Related Id(s): PR-11521

  • A gen_tcp socket using the inet driver and {packet,4} had a bug if receiving a packet with size just below INT_MAX.

    That packet size wrapped in size calculations and made the received data overwrite its allocation and trash allocator metadata and subsequent block(s), causing the VM to crash.

    This made it possible for anyone to remotely crash an Erlang node that used {packet,4} on a reachable socket.

    This bug has been corrected.

    Own Id: OTP-20334
    Related Id(s): PR-11533, CVE-2026-75538

Full runtime dependencies of erts-17.0.6

kernel-9.0, sasl-3.3, stdlib-4.1

inets-9.7.2

The inets-9.7.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • The dets and mnesia mod_auth backends used a key that did not include the directory path, so all require_user/require_group records collapsed into one per-listener namespace. A user authorized for one protected directory could authenticate against any other protected directory served by the same listener. {path, Directory} is now included in the auth backend key, scoping records per directory as documented.

    Own Id: OTP-20264
    Related Id(s): PR-11546 CVE-2026-74994

  • Requests specifying both Transfer-Encoding and Content-Length headers are now rejected with 400 Bad Request, per RFC 9112 Section 6.3. Previously such requests could be used for CL.TE request-smuggling/desync attacks against reverse proxies in front of httpd.

    Own Id: OTP-20268
    Related Id(s): PR-11547 CVE-2026-73812

  • httpd accepted the obsolete header line-folding syntax (RFC 9112 Section 5.2, a continuation line beginning with space/tab), silently treating the folded continuation as a separate header. This allowed CL.TE-style request smuggling when httpd was placed behind a folding-aware proxy. Such requests are now rejected with 400 Bad Request.

    Own Id: OTP-20269
    Related Id(s): PR-11544 CVE-2026-66357

  • A header such as Content-Length : 6 (whitespace before the colon) was previously silently dropped, causing the content length to default to 0 and the body bytes to be misinterpreted as a pipelined request (CL.0 smuggling). Per RFC 7230 Section 3.2.4, such headers are now rejected with 400 Bad Request.

    Own Id: OTP-20270
    Related Id(s): PR-11545 CVE-2026-73276

  • A new httpd option request_timeout (default 60 seconds, renamed from the interim max_body_read_timeout) bounds the idle time between reads of a request body/message. The server now also sends 408 Request Timeout when the min_bytes_per_second floor is hit, and keep_alive_timeout measurement was corrected so the timer is cancelled as soon as new data arrives rather than only after full header parsing; keep_alive_timeout and request_timeout now also accept infinity to disable the timeout.

    Own Id: OTP-20271
    Related Id(s): PR-11543 CVE-2026-71380

  • mod_auth, mod_security, and mod_get compared resolved filesystem paths against configured protected-directory patterns without normalizing repeated slashes or filesystem case. On case-insensitive filesystems (macOS, Windows) or with repeated slashes, a request could resolve to a protected resource while evading the directory match. Paths are now canonicalized (slash-collapsed, and case-normalized when the filesystem is case-insensitive) before the authorization decision.

    Own Id: OTP-20279
    Related Id(s): PR-11542 CVE-2026-73270 CVE-2026-66835

  • A request with an invalid chunked transfer-encoding chunk size previously caused the httpd connection handler to hang indefinitely without requiring further input from the client. This leaked a process per request and could be used to exhaust server resources (denial of service). Invalid chunk sizes are now rejected immediately with an error response, and the connection is closed.

    Own Id: OTP-20306
    Related Id(s): PR-11539 CVE-2026-69664

  • max_body_size was previously enforced only after a complete chunk had been received, allowing a single oversized chunk to be buffered in full before the limit was checked — undermining the memory-exhaustion protection the option is meant to provide. The limit is now enforced incrementally as chunk data arrives, rejecting the request as soon as the configured size is exceeded.

    Own Id: OTP-20307
    Related Id(s): PR-11540 CVE-2026-74835

  • The documented default of 150 for the max_clients option was not applied by the implementation, allowing an unbounded number of concurrent clients to connect regardless of configuration. The default is now correctly enforced.

    Own Id: OTP-20308
    Related Id(s): PR-11541 CVE-2026-70399

  • Fixed a bug where httpd failed to start when configured with {socket_type, {ip_comm, SockOpts}} and a fixed (non-zero) port.

    Own Id: OTP-20342
    Related Id(s): PR-11548

  • httpc now enforces a limit on the total size of response headers and response body, preventing unbounded memory allocation when connecting to a malicious or malfunctioning server. The new max_header_size and max_body_size request options can be used to override the default limit (10240 bytes for headers). Additionally, httpc now validates that the Content-Length header contains only digits before use, avoiding a crash on malformed responses.

    Own Id: OTP-20343
    Related Id(s): PR-11538 CVE-2026-55951 CVE-2026-71562

Full runtime dependencies of inets-9.7.2

erts-14.0, kernel-9.0, mnesia-4.12, public_key-1.13, runtime_tools-1.8.14, ssl-9.0, stdlib-5.0, stdlib-6.0

megaco-4.9.2

The megaco-4.9.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Numeric fields in megaco text-encoded messages are now validated for digit-string length before integer conversion, improving robustness of the text decoder. Per-field digit limits based on the H.248.1 ASN.1 type constraints are enforced (e.g., 10 digits for UINT32, 2 digits for timer values), along with a 100 KB overall message size cap at the scanner entry point. The binary (BER/PER) codec is not affected.

    Own Id: OTP-20234
    Related Id(s): PR-11325

Full runtime dependencies of megaco-4.9.2

asn1-3.0, debugger-4.0, erts-12.0, et-1.5, kernel-8.0, runtime_tools-1.8.14, stdlib-2.5

mnesia-4.26.2

The mnesia-4.26.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • A transaction iterating a table (first/1, last/1, next/2, prev/2, select, select_reverse on non-ordered_set) leaked a safe_fixtable hold when the coordinator was killed by an external signal. The table remained fixed for the lifetime of the node, preventing space reclamation of deleted objects.

    Own Id: OTP-20347
    Related Id(s): PR-11517

  • Fixed a race condition where mnesia_controller could crash if a table was deleted while mnesia:set_master_nodes/2 was being processed.

    Own Id: OTP-20351
    Related Id(s): PR-11554

Full runtime dependencies of mnesia-4.26.2

erts-9.0, kernel-5.3, stdlib-5.0

public_key-1.21.5

The public_key-1.21.5 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Retain lost CommonName length relaxation.

    Own Id: OTP-20321
    Related Id(s): GH-11240, PR-11358

Full runtime dependencies of public_key-1.21.5

asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0

snmp-5.20.5

The snmp-5.20.5 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • The SNMP PDU decoder now bounds the byte length accepted for INTEGER, Counter32, Gauge32/Unsigned32, TimeTicks, and Counter64 values during decoding (4, 5, 5, 5, and 9 bytes respectively, matching the SMIv2 value ranges), instead of accepting an arbitrarily large byte string and converting it to an integer.

    Own Id: OTP-20346
    Related Id(s): PR-11538 CVE-2026-70405

Full runtime dependencies of snmp-5.20.5

asn1-5.4, crypto-4.6, erts-12.0, kernel-8.0, mnesia-4.12, runtime_tools-1.8.14, stdlib-5.0

ssh-6.0.5

The ssh-6.0.5 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed a bug where multiple subsystem requests could succeed on same ssh channel which is forbidden by RFC 4254 §6.5

    Own Id: OTP-20284
    Related Id(s): PR-11437

Full runtime dependencies of ssh-6.0.5

crypto-5.7, erts-14.0, kernel-10.3, public_key-1.6.1, runtime_tools-1.15.1, stdlib-8.0

ssl-11.7.5

Note! The ssl-11.7.5 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.

   On a full OTP 29 installation, also the following runtime
   dependency has to be satisfied:
   -- public_key-1.21.1 (first satisfied in OTP 29.0.1)

Fixed Bugs and Malfunctions

  • Debugging keylog_hs callback used for logging handshake secrets on failed connections swapped the argument order in logging function confusing server and client side. The bug was introduced in OTP 28.5

    Own Id: OTP-20350
    Related Id(s): ERIERL-1354, PR-11553

Improvements and New Features

  • Hardening improvements of the ssl application.

    TLS distribution now defaults to TLS-1.3 instead of TLS-1.2 (TLS-1.2 is kept as fallback for rolling upgrades).

    TLS-1.2 server with {verify, verify_peer} now defaults reuse_sessions to false to mitigate the Triple Handshake attack (RFC 7627). Set {reuse_sessions, true} explicitly to restore previous behavior.

    Various missing or faulty sanity checks added and TLS alerts adjusted to comply with RFC MUST requirements, including: signature algorithm validation for intermediate certificates, TLS-1.3 session_id echo, pre_shared_key extension ordering, and renegotiation_info enforcement.

    Hardened and improved CRL support. Introduces new option allowed_hosts for the optional CRL HTTP fetching feature to restrict which hosts may be contacted. Internal/loopback IPs are now blocked by default (SSRF protection).

    TLS-1.3 client ticket handling is more robust (locked tickets are released on client crash). Server TLS-1.3 ticket handling and anti-replay Bloom filter performance are optimized.

    DTLS duplicate ChangeCipherSpec handling simplified, fixing potential state machine confusion (GH-11075).

    Process state formatting no longer leaks secrets in crash logs.

    Own Id: OTP-20289
    Related Id(s): PR-11478

Full runtime dependencies of ssl-11.7.5

crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public_key-1.21.1, runtime_tools-1.15.1, stdlib-7.0

stdlib-8.0.4

The stdlib-8.0.4 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed a bug in unicode_util:gc/1 where the grapheme cluster segmentation of $\r (not followed by $\n) would decompose binary continuations into mixed chardata. This caused string:trim/3 (and string:chomp/1) to return incorrect results or crash when trimming strings containing binaries followed by another list element.

    Own Id: OTP-20296
    Related Id(s): GH-11380, PR-11464

  • record_info/2 will now mark tuple records as used.

    Own Id: OTP-20301
    Related Id(s): ERIERL-1345, PR-11470

  • uri_string:parse/1 now rejects URIs with an unreasonably long port component (more than 5 digits) instead of attempting to convert an arbitrarily large digit string to an integer.

    Own Id: OTP-20344
    Related Id(s): PR-11538 CVE-2026-59696

Full runtime dependencies of stdlib-8.0.4

compiler-5.0, crypto-4.5, erts-16.0.3, kernel-11.0, sasl-3.0, syntax_tools-3.2.1

tools-4.2.2

The tools-4.2.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • tools: fixes tprof not stopping tracing

    A call to tprof:enable_trace(new|existing) starts tracing processes. To stop it, one calls tprof:disable_trace(new|existing). However, the guard to stop tracing was matching on new_processes | existing_processes. The return happens to say 0 processes are traced now, but the tracing did not stop. This issue has been fixed.

    Own Id: OTP-20302
    Related Id(s): PR-11481

Full runtime dependencies of tools-4.2.2

compiler-8.5, crypto-5.9, erts-15.0, kernel-10.0, public_key-1.21, runtime_tools-2.1, stdlib-6.0

Thanks to

Andrew Bennett, ausimian, Laurynas Četyrkinas, ruslandoga, Thomas Cioppettini

v29.0.5: OTP 29.0.5

Compare Source

Patch Package:           OTP 29.0.5
Git Tag:                 OTP-29.0.5
Date:                    2026-08-04
Trouble Report Id:       OTP-20137, OTP-20275
Seq num:                 GH-11402, PR-11110, PR-11409
System:                  OTP
Release:                 29
Application:             erts-17.0.5, ssh-6.0.4
Predecessor:             OTP 29.0.4

Check out the git tag OTP-29.0.5, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.

erts-17.0.5

The erts-17.0.5 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed a regression in the previous patch release that prevented epmd from binding to localhost.

    Own Id: OTP-20275
    Related Id(s): GH-11402, PR-11409

Full runtime dependencies of erts-17.0.5

kernel-9.0, sasl-3.3, stdlib-4.1

ssh-6.0.4

The ssh-6.0.4 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • The SSH client and server now reject incoming packets not aligned to the cipher block size as required by RFC 4253 §6. For CBC ciphers, a timing-safe "packet discard" mechanism (CVE-2008-5161 mitigation) ensures structural errors are indistinguishable from MAC failures before disconnecting. AEAD and encrypt-then-MAC modes disconnect immediately.

    Own Id: OTP-20137
    Related Id(s): PR-11110

Full runtime dependencies of ssh-6.0.4

crypto-5.7, erts-14.0, kernel-10.3, public_key-1.6.1, runtime_tools-1.15.1, stdlib-8.0

v29.0.4: OTP 29.0.4

Compare Source

Patch Package:           OTP 29.0.4
Git Tag:                 OTP-29.0.4
Date:                    2026-07-27
Trouble Report Id:       OTP-20136, OTP-20143, OTP-20214, OTP-20229,
                         OTP-20237, OTP-20239, OTP-20240, OTP-20241,
                         OTP-20242, OTP-20243, OTP-20244, OTP-20245,
                         OTP-20248, OTP-20250, OTP-20251, OTP-20257,
                         OTP-20258, OTP-20259, OTP-20260, OTP-20261
Seq num:                 CVE-2026-42792, CVE-2026-47078,
                         CVE-2026-54890, CVE-2026-55737,
                         CVE-2026-55953, CVE-2026-58227, ERIERL-1341,
                         GH-11319, GH-11332, GH-11368,
                         GH-SA-622p-qfh6-c352, GH-SA-7xgh-gmgf-q2g7,
                         PR-11239, PR-11297, PR-11303, PR-11323,
                         PR-11330, PR-11331, PR-11333, PR-11334,
                         PR-11336, PR-11337, PR-11341, PR-11343,
                         PR-11369, PR-11372, PR-11374, PR-11386,
                         PR-27944
System:                  OTP
Release:                 29
Application:             compiler-10.0.3, crypto-5.9.2,
                         diameter-2.7.2, erts-17.0.4, megaco-4.9.1,
                         public_key-1.21.4, ssh-6.0.3, ssl-11.7.4,
                         stdlib-8.0.3
Predecessor:             OTP 29.0.3

Check out the git tag OTP-29.0.4, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.

POTENTIAL INCOMPATIBILITIES

  • Mitigated a denial of service attack in epmd.

    Thanks to Ryan Moore for finding and responsibly disclosing this vulnerability to the Erlang/OTP project.

    Own Id: OTP-20136
    Application(s): erts
    Related Id(s): PR-11386, CVE-2026-42792

compiler-10.0.3

The compiler-10.0.3 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • compiler: Fix an internal consistency check failure with setelement

    Own Id: OTP-20261
    Related Id(s): GH-11368, PR-11374

Full runtime dependencies of compiler-10.0.3

crypto-5.1, erts-13.0, kernel-8.4, stdlib-8.0

crypto-5.9.2

The crypto-5.9.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed crash in crypto:macN/5 when supplied MacLength was greater than length of what the underlying hash returned.

    Own Id: OTP-20239
    Related Id(s): PR-11239

  • Fixed segfault in crypto:aead_cipher_init_nif when argument validation fails.

    Own Id: OTP-20241
    Related Id(s): PR-11330

  • Fix cipher key buffer overread for chacha20_poly1305.

    Own Id: OTP-20244
    Related Id(s): PR-11337

Full runtime dependencies of crypto-5.9.2

erts-9.0, kernel-6.0, stdlib-3.9

diameter-2.7.2

The diameter-2.7.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fix infinite loop in diameter_dist:route_session/2 when avp other than Session-Id has zero length.

    Own Id: OTP-20242
    Related Id(s): PR-11331

  • Fix crash in diameter_dist:route_session/2 when Session-Id (code: 263) avp has zero length.

    Own Id: OTP-20243
    Related Id(s): PR-11333

Full runtime dependencies of diameter-2.7.2

erts-10.0, kernel-3.2, ssl-9.0, stdlib-5.0

erts-17.0.4

The erts-17.0.4 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Mitigated a denial of service attack in epmd.

    Thanks to Ryan Moore for finding and responsibly disclosing this vulnerability to the Erlang/OTP project.

    Own Id: OTP-20136
    Related Id(s): PR-11386, CVE-2026-42792

    *** POTENTIAL INCOMPATIBILITY ***

  • Fixed heap corruption when an invalidly encoded tuple with an arity of 2^31 or larger is decoded from Erlang's External Term Format (binary_to_term).

    Own Id: OTP-20214
    Related Id(s): PR-11297, CVE-2026-55737

  • When send_timeout is set and send_timeout_close is set to true, a 'tcp_closed' message is expected when the timeout occurs, but that (message) was not delivered. This has now been fixed.

    Own Id: OTP-20257
    Related Id(s): GH-11319

  • A crafted External Term Format (ETF) payload could crash the runtime system.

    Thanks to Paul Guyot for finding and responsibly disclosing this vulnerability to the Erlang/OTP project.

    Own Id: OTP-20259
    Related Id(s): PR-11386, CVE-2026-54890

  • Fixed a rounding error in 16-bit float conversion.

    Own Id: OTP-20260
    Related Id(s): GH-11332, PR-11334

Full runtime dependencies of erts-17.0.4

kernel-9.0, sasl-3.3, stdlib-4.1

megaco-4.9.1

The megaco-4.9.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed a buffer overflow in the megaco flex scanner C driver. A property parm name exceeding 452 bytes in a text-encoded H.248 message could overflow a fixed-size error buffer, crashing the VM. The sprintf calls have been replaced with bounded snprintf.

    Own Id: OTP-20237
    Related Id(s): GH-SA-7xgh-gmgf-q2g7, PR-11323

Full runtime dependencies of megaco-4.9.1

asn1-3.0, debugger-4.0, erts-12.0, et-1.5, kernel-8.0, runtime_tools-1.8.14, stdlib-2.5

public_key-1.21.4

The public_key-1.21.4 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • A certificate chain with crafted policyMappings extensions could cause exponential memory consumption during path validation, exploitable via TLS handshake. Chains exceeding a node-count cap are now rejected with {bad_cert, policy_tree_exceeded}.

    Own Id: OTP-20251
    Related Id(s): GH-SA-622p-qfh6-c352, PR-11372

Full runtime dependencies of public_key-1.21.4

asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0

ssh-6.0.3

The ssh-6.0.3 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • DH key exchange now enforces strict bounds (1 < e/f < p-1, 1 < K < p-1) on all paths, matching OpenSSH and Go. No interop impact.

    Own Id: OTP-20229
    Related Id(s): PR-11303

  • Validate DH group parameters (P, G) received from the server during DH-GEX key exchange. The client now rejects groups where P is smaller than 2048 bits or G is not in the range (1, P-1). The default minimum in dh_gex_limits has been raised to 2048 on both client and server.

    Own Id: OTP-20258
    Related Id(s): ERIERL-1341, PR-11369

Full runtime dependencies of ssh-6.0.3

crypto-5.7, erts-14.0, kernel-10.3, public_key-1.6.1, runtime_tools-1.15.1, stdlib-8.0

ssl-11.7.4

Note! The ssl-11.7.4 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.

   On a full OTP 29 installation, also the following runtime
   dependency has to be satisfied:
   -- public_key-1.21.1 (first satisfied in OTP 29.0.1)

Fixed Bugs and Malfunctions

  • Add pre TLS-1.3 client side validation of servers algorithm selection being part of clients offered algorithms, preventing in worst case MITM circumventing validation of server certificate tricking the client to trust the malicious MITM as it was a valid server. Note this check is already performed for TLS-1.3 clients.

    Own Id: OTP-20240
    Related Id(s): PR-11336, CVE-2026-55953

  • Prevent invalid cert chains to create cycles in chain building code used to handle chains that could be unordered or contain extraneous certs. This avoids a DoS attack possibility.

    Own Id: OTP-20245
    Related Id(s): PR-11343, CVE-2026-58227

  • Clarify that rsa_psk and anonymous key exchange algorithms are considered legacy. Also harden rsa_psk in same way as normal rsa key exchange.

    Own Id: OTP-20248
    Related Id(s): PR-11341

  • Harden SSL application to conform with best practice and RFC's. This will mostly improve error messages and conserve memory usage.

    Own Id: OTP-20250
    Related Id(s): PR-27944

  • A certificate chain with crafted policyMappings extensions could cause exponential memory consumption during path validation, exploitable via TLS handshake. Chains exceeding a node-count cap are now rejected with {bad_cert, policy_tree_exceeded}.

    Own Id: OTP-20251
    Related Id(s): GH-SA-622p-qfh6-c352, PR-11372

Full runtime dependencies of ssl-11.7.4

crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public_key-1.21.1, runtime_tools-1.15.1, stdlib-7.0

stdlib-8.0.3

The stdlib-8.0.3 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed a bug where zip:unzip/1,2 and zip:extract/1,2 were vulnerable to a relative path traversal attack. A crafted zip archive containing entry names such as ../x/y could have caused files to be written outside the intended extraction directory.

    Thanks to Jonatan Männchen and Zhang Delong for finding and responsibly disclosing this vulnerability to the Erlang/OTP project.

    Own Id: OTP-20143
    Related Id(s): PR-11386, CVE-2026-47078

Full runtime dependencies of stdlib-8.0.3

compiler-5.0, crypto-4.5, erts-16.0.3, kernel-11.0, sasl-3.0, syntax_tools-3.2.1

Thanks to

a1x-an, Jonatan Männchen

v29.0.3: OTP 29.0.3

Compare Source

Patch Package:           OTP 29.0.3
Git Tag:                 OTP-29.0.3
Date:                    2026-07-02
Trouble Report Id:       OTP-20173, OTP-20183, OTP-20185, OTP-20186,
                         OTP-20190, OTP-20191, OTP-20194, OTP-20196,
                         OTP-20197, OTP-20198, OTP-20199, OTP-20200,
                         OTP-20201, OTP-20206, OTP-20207, OTP-20208,
                         OTP-20215, OTP-20216, OTP-20217, OTP-20220,
                         OTP-20222, OTP-20226, OTP-20227, OTP-20230,
                         OTP-20231, OTP-20232, OTP-20233
Seq num:                 CVE-2026-53422, CVE-2026-54886,
                         CVE-2026-54887, CVE-2026-54891,
                         CVE-2026-55950, CVE-2026-55952, ERIERL-1333,
                         GH-SA-7wp4-pc27-2vj9, GH-SA-h9pw-h5w4-h976,
                         PR-11209, PR-11215, PR-11219, PR-11230,
                         PR-11239, PR-11244, PR-11247, PR-11250,
                         PR-11259, PR-11268, PR-11269, PR-11270,
                         PR-11271, PR-11281, PR-11282, PR-11283,
                         PR-11289, PR-11294, PR-11295, PR-11299,
                         PR-11302, PR-11306, PR-11307, PR-11309,
                         PR-11311
System:                  OTP
Release:                 29
Application:             common_test-1.31.1, compiler-10.0.2,
                         crypto-5.9.1, dialyzer-6.0.2, erts-17.0.3,
                         kernel-11.0.3, public_key-1.21.3, ssh-6.0.2,
                         ssl-11.7.3, stdlib-8.0.2
Predecessor:             OTP 29.0.2

Check out the git tag OTP-29.0.3, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.

common_test-1.31.1

The common_test-1.31.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed a crash in ct_netconfc that occurred when the remote server closed the SSH connection during NETCONF subsystem negotiation.

    Own Id: OTP-20191
    Related Id(s): ERIERL-1333, PR-11230

Full runtime dependencies of common_test-1.31.1

compiler-10.0, crypto-4.5, debugger-4.1, erts-7.0, ftp-1.0, inets-6.0, kernel-11.0, observer-2.1, runtime_tools-1.8.16, sasl-2.5, snmp-5.1.2, ssh-4.0, stdlib-8.0, syntax_tools-1.7, tools-3.2, xmerl-1.3.8

compiler-10.0.2

The compiler-10.0.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Several compiler bugs that could crash the compiler or generate incorrect code in rare circumstances have been fixed.

    Own Id: OTP-20222
    Related Id(s): PR-11219

Full runtime dependencies of compiler-10.0.2

crypto-5.1, erts-13.0, kernel-8.4, stdlib-8.0

crypto-5.9.1

The crypto-5.9.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • crypto:compute_key/4 for eddh and crypto:generate_key/2,3 for eddh/eddsa now raise an error:{notsup, Info, Description} exception instead of returning the atom notsup when the underlying cryptolib lacks support.

    Own Id: OTP-20215
    Related Id(s): PR-11302

Full runtime dependencies of crypto-5.9.1

erts-9.0, kernel-6.0, stdlib-3.9

dialyzer-6.0.2

The dialyzer-6.0.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fix a bug with native record sets in erl_types.erl

    Own Id: OTP-20201

Full runtime dependencies of dialyzer-6.0.2

compiler-10.0, erts-12.0, kernel-8.0, stdlib-5.0, syntax_tools-2.0

erts-17.0.3

The erts-17.0.3 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed an undefined behavior in the internal erts_qsort() function, which could have been the cause of a beam crash seen when updating large maps.

    Own Id: OTP-20185
    Related Id(s): PR-11215

  • Calculating bxor of the largest supported positive integer (erlang:system_info(max_integer)) and -1 would return [] instead of a raising a system_limit exception.

    Own Id: OTP-20208
    Related Id(s): PR-11269

  • Fix possible race between ets:delete/1 and terminating process with a fixation on the same table.

    Own Id: OTP-20217
    Related Id(s): PR-11283

  • A few code generation issues for the JIT on AArch64 (ARM64) have been fixed.

    For all platforms, the loader will reject some invalid BEAM files earlier.

    Own Id: OTP-20226
    Related Id(s): PR-11299

  • On 32-bit computers, the md5 BIFs would return an incorrect MD5 checksum for data of size 4GiB or more.

    Own Id: OTP-20227
    Related Id(s): PR-11289

Full runtime dependencies of erts-17.0.3

kernel-9.0, sasl-3.3, stdlib-4.1

kernel-11.0.3

The kernel-11.0.3 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • inet:info/1 could crash when calling for a closing (port) socket.

    Own Id: OTP-20173

  • Handling of the truncation bit in inet_res has been fixed so it properly falls back to querying over TCP after a truncated UDP reply.

    This fixes a bug introduced in OTP-28.4.2 - kernel-10.6.2 making a truncated UDP answer fail to parse and never execute the fallback, instead the name resolve operation fails.

    Own Id: OTP-20199
    Related Id(s): PR-11247

Full runtime dependencies of kernel-11.0.3

crypto-5.8, erts-17.0, sasl-3.0, stdlib-8.0

public_key-1.21.3

The public_key-1.21.3 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Hardened OCSP response verification by using constant-time hash comparisons and rejecting responses exceeding 100 KB before ASN.1 decoding.

    Own Id: OTP-20197
    Related Id(s): PR-11239

Full runtime dependencies of public_key-1.21.3

asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0

ssh-6.0.2

The ssh-6.0.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed a path-existence oracle in the SFTP server where SSH_FXP_REALPATH requests with .. components could bypass the configured root directory isolation, allowing an authenticated client to determine whether arbitrary paths exist on the host filesystem.

    Own Id: OTP-20183
    Related Id(s): GH-SA-h9pw-h5w4-h976, PR-11294, CVE-2026-53422

  • Fixed an infinite loop in the SFTP server triggered when receiving SSH_MSG_CHANNEL_EXTENDED_DATA on an SFTP channel, which caused the channel process to spin indefinitely on CPU without consuming its message queue.

    Own Id: OTP-20186
    Related Id(s): GH-SA-7wp4-pc27-2vj9, PR-11295, CVE-2026-54886

  • Fixed mlkem768x25519 hybrid key exchange failing intermittently with "incorrect signature" when the X25519 shared secret had a leading zero byte. The shared secret is now encoded as a fixed-width 32-byte string per the specification.

    Own Id: OTP-20196
    Related Id(s): PR-11209

  • Fixed a race condition where SSH keepalive responses could be matched to unrelated pending requests due to incorrect request queue ordering. Requests are now matched in the order they were sent.

    Own Id: OTP-20198
    Related Id(s): PR-11244

  • The SFTP server now caps the read length in SSH_FXP_READ requests to 255 KiB (matching OpenSSH's SFTP_MAX_READ_LENGTH), preventing excessive memory allocation when clients request large reads.

    Own Id: OTP-20200
    Related Id(s): PR-11259

  • Removed a server-side workaround (OTP-14827, introduced in OTP 20) that accepted SHA-1 user-auth signatures from clients identifying as OpenSSH 7.x when rsa-sha2-* was negotiated. The workaround addressed a distro-specific build issue in 2017 that no longer exists. Clients affected by this removal (extremely unlikely — requires a 10-year-old unpatched OpenSSH build) will see authentication failures and must upgrade.

    Own Id: OTP-20206
    Related Id(s): PR-11268

Full runtime dependencies of ssh-6.0.2

crypto-5.7, erts-14.0, kernel-10.3, public_key-1.6.1, runtime_tools-1.15.1, stdlib-8.0

ssl-11.7.3

Note! The ssl-11.7.3 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.

   On a full OTP 29 installation, also the following runtime
   dependency has to be satisfied:
   -- public_key-1.21.1 (first satisfied in OTP 29.0.1)

Fixed Bugs and Malfunctions

  • Correct small behavior bugs that occasionally could cause DTLS connection errors, unwanted behavior for legacy DHE_DSS, hiding of a distribution config error, and possible unorderly process tree shutdown.

    Own Id: OTP-20190
    Related Id(s): PR-11250

  • Initialize DTLS cookie to random value to avoid DoS attack with forged cookie during startup window.

    Own Id: OTP-20194
    Related Id(s): PR-11271, CVE-2026-54887

  • Guard TLS client for MITM injection of application data during "plain-text-window" during handshake.

    Own Id: OTP-20207
    Related Id(s): PR-11270, CVE-2026-54891

  • Improve error handling of TLS PSK sending ILLIGAL_PARMETER alert if binders and PSK-identities are not matched. Also mend recovery mechanism of ticket and session stores to be as resilient as possible to intermediate bugs.

    Own Id: OTP-20216
    Related Id(s): PR-11282, CVE-2026-55952

  • Fix race condition that could be used to DoS attack DTLS servers.

    Own Id: OTP-20220
    Related Id(s): PR-11306, CVE-2026-55950

  • A TLS-1.3 stateless session ticket with obfuscated_ticket_age set to zero was incorrectly accepted without checking the server-side ticket lifetime or the RFC 8446 Section 8.3 freshness window. The server now always validates ticket age using its own timestamp regardless of the client-reported age value.

    Own Id: OTP-20230
    Related Id(s): PR-11307

  • TLS-1.3 client rejects a second HelloRetryRequest as requiered in RFC 8446 Section 4.1.4

    Own Id: OTP-20231
    Related Id(s): PR-11309

  • A busy client node could self-trigger a ticket store crash if unlucky with scheduling if auto mode is used.

    Own Id: OTP-20232
    Related Id(s): PR-11311

  • Correct spec for CRL API

    Own Id: OTP-20233
    Related Id(s): PR-11281

Full runtime dependencies of ssl-11.7.3

crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public_key-1.21.1, runtime_tools-1.15.1, stdlib-7.0

stdlib-8.0.2

The stdlib-8.0.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Several compiler bugs that could crash the compiler or generate incorrect code in rare circumstances have been fixed.

    Own Id: OTP-20222
    Related Id(s): PR-11219

Full runtime dependencies of stdlib-8.0.2

compiler-5.0, crypto-4.5, erts-16.0.3, kernel-11.0, sasl-3.0, syntax_tools-3.2.1

Thanks to

Cole Christensen, Nick Krichevsky, Stefan Grundmann

v29.0.2: OTP 29.0.2

Compare Source

Patch Package:           OTP 29.0.2
Git Tag:                 OTP-29.0.2
Date:                    2026-06-10
Trouble Report Id:       OTP-20057, OTP-20149, OTP-20150, OTP-20151,
                         OTP-20153, OTP-20154, OTP-20155, OTP-20156,
                         OTP-20160, OTP-20161, OTP-20162, OTP-20163,
                         OTP-20165, OTP-20166, OTP-20170, OTP-20172,
                         OTP-20174, OTP-20178, OTP-20181
Seq num:                 CVE-2026-48855, CVE-2026-48856,
                         CVE-2026-48858, CVE-2026-48859,
                         CVE-2026-48860, CVE-2026-49759,
                         CVE-2026-49760, GH-11104, GH-11105, GH-11152,
                         GH-SA-24cv-hwgr-37fq, GH-SA-3w6p-vwhf-wvp4,
                         GH-SA-6f4f-chj5-5g97, GH-SA-gp7x-mfv6-52cv,
                         GH-SA-m75x-4vwg-ggjh, GH-SA-pv7g-pjrq-x2fh,
                         GH-SA-xcxj-5pg2-v72j, PR-11141, PR-11145,
                         PR-11146, PR-11148, PR-11154, PR-11157,
                         PR-11168, PR-11181, PR-11186, PR-11192,
                         PR-11193, PR-11195, PR-11199, PR-11205,
                         PR-11212, PR-1234, PR-27384
System:                  OTP
Release:                 29
Application:             dialyzer-6.0.1, diameter-2.7.1,
                         erl_interface-5.8.1, erts-17.0.2, ftp-1.2.6,
                         inets-9.7.1, kernel-11.0.2, mnesia-4.26.1,
                         public_key-1.21.2, ssh-6.0.1, ssl-11.7.2,
                         stdlib-8.0.1, tools-4.2.1
Predecessor:             OTP 29.0.1

Check out the git tag OTP-29.0.2, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp_patch_apply' tool. For information on install requirements, see descriptions for each application version below.

dialyzer-6.0.1

The dialyzer-6.0.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fix native record bugs in Dialyzer

    Own Id: OTP-20178
    Related Id(s): PR-11199

Full runtime dependencies of dialyzer-6.0.1

compiler-10.0, erts-12.0, kernel-8.0, stdlib-5.0, syntax_tools-2.0

diameter-2.7.1

The diameter-2.7.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed return value documentation of diameter:service_info(SvcName, statistics)

    Own Id: OTP-20150
    Related Id(s): GH-11105, PR-11146

Full runtime dependencies of diameter-2.7.1

erts-10.0, kernel-3.2, ssl-9.0, stdlib-5.0

erl_interface-5.8.1

The erl_interface-5.8.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

erts-17.0.2

The erts-17.0.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • A buffer overflow error when parsing SCTP ERROR or ABORT chunks has been fixed.

    This could lead to stack corruption and VM crash, but ultimately with hard work by an attacker be refined into maybe even remote code execution.

    Own Id: OTP-20165
    Related Id(s): GH-SA-6f4f-chj5-5g97, PR-1234, CVE-2026-49759

Full runtime dependencies of erts-17.0.2

kernel-9.0, sasl-3.3, stdlib-4.1

ftp-1.2.6

The ftp-1.2.6 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • FTP client default connections that use the so called passive mode of FTP fails to properly validating the response IP of the server, hence a malicious or compromised FTP server could redirect the data connection to an arbitrary host, enabling s server-side request forgery (SSRF) and FTP bounce attacks.

    Own Id: OTP-20166
    Related Id(s): GH-SA-24cv-hwgr-37fq, PR-11186, CVE-2026-48858

Full runtime dependencies of ftp-1.2.6

erts-7.0, kernel-6.0, runtime_tools-1.15.1, ssl-10.2, stdlib-3.5

inets-9.7.1

The inets-9.7.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • The HTTP client (httpc) now removes Authorization, Proxy-Authorization, Cookie, Referer, and Origin headers when following a redirect to a different host or port. Previously these headers were forwarded verbatim, potentially leaking credentials to unintended targets.

    This follows the requirements of RFC 9110 §15.4.

    Own Id: OTP-20155
    Related Id(s): GH-SA-m75x-4vwg-ggjh, PR-11212, CVE-2026-48856

Full runtime dependencies of inets-9.7.1

erts-14.0, kernel-9.0, mnesia-4.12, public_key-1.13, runtime_tools-1.8.14, ssl-9.0, stdlib-5.0, stdlib-6.0

kernel-11.0.2

The kernel-11.0.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • gen_tcp_socket accept should explicitly inherit the same options as plain gen_tcp.

    Own Id: OTP-20057

Full runtime dependencies of kernel-11.0.2

crypto-5.8, erts-17.0, sasl-3.0, stdlib-8.0

mnesia-4.26.1

The mnesia-4.26.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed docs of mnesia:write/3 to clarify when a transaction can terminate.

    Own Id: OTP-20149
    Related Id(s): GH-11104, PR-11145

Full runtime dependencies of mnesia-4.26.1

erts-9.0, kernel-5.3, stdlib-5.0

public_key-1.21.2

The public_key-1.21.2 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Add missing macro reference for legacy algorithms md5 and sha224. This mainly improves error handling.

    Own Id: OTP-20172
    Related Id(s): PR-11195

Full runtime dependencies of public_key-1.21.2

asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0

ssh-6.0.1

The ssh-6.0.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fixed a timing-based username enumeration vulnerability during password authentication with the user_passwords option. A dummy PBKDF2 computation is now performed for invalid usernames to match the response time of valid ones.

    Own Id: OTP-20153
    Related Id(s): GH-SA-3w6p-vwhf-wvp4, PR-11157, CVE-2026-48859

  • Fixed SSH_FXP_READLINK handler in ssh_sftpd to strip the backend root prefix from symlink targets before returning them to the client, preventing disclosure of the server's absolute filesystem path when the root option is configured.

    Own Id: OTP-20162
    Related Id(s): GH-SA-pv7g-pjrq-x2fh, PR-11192, CVE-2026-48855

  • Fixed a race condition where SSH keep-alive responses could consume pending channel open requests, causing channel setup to fail silently.

    Own Id: OTP-20181
    Related Id(s): PR-11205

Full runtime dependencies of ssh-6.0.1

crypto-5.7, erts-14.0, kernel-10.3, public_key-1.6.1, runtime_tools-1.15.1, stdlib-8.0

ssl-11.7.2

Note! The ssl-11.7.2 application cannot be applied independently of other applications on an arbitrary OTP 29 installation.

   On a full OTP 29 installation, also the following runtime
   dependency has to be satisfied:
   -- public_key-1.21.1 (first satisfied in OTP 29.0.1)

Fixed Bugs and Malfunctions

  • Fix miscellanies issues that could cause unnecessary memory consumption and in some less common scenarios or configurations cause connection failures.

    Own Id: OTP-20154
    Related Id(s): PR-11148

  • Erlang distribution over TLS run with the kernel 'check_ip' flag now properly enforce connecting nodes to be on the same LAN.

    Own Id: OTP-20156
    Related Id(s): GH-SA-gp7x-mfv6-52cv, PR-11181, CVE-2026-48860

  • Enhance error message, by fixing typo of atom in new error message related to `public_key` CVE-2026-42790 solution.

    Own Id: OTP-20161
    Related Id(s): PR-11148

  • Corrected SNI handling for TLS-1.3 only server, could cause connection failures if supported signature algorithms where changed by SNI option update.

    Own Id: OTP-20174
    Related Id(s): PR-27384

Full runtime dependencies of ssl-11.7.2

crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public_key-1.21.1, runtime_tools-1.15.1, stdlib-7.0

stdlib-8.0.1

The stdlib-8.0.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Fix a bug where a tuple record operation within a native record anonymous update can crash.

    Own Id: OTP-20151
    Related Id(s): PR-11141

  • Fixed some bugs in io_lib:bformat/2 and native record printing.

    Own Id: OTP-20170
    Related Id(s): PR-11154

Full runtime dependencies of stdlib-8.0.1

compiler-5.0, crypto-4.5, erts-16.0.3, kernel-11.0, sasl-3.0, syntax_tools-3.2.1

tools-4.2.1

The tools-4.2.1 application can be applied independently of other applications on a full OTP 29 installation.

Fixed Bugs and Malfunctions

  • Xref could crash instead of returning an appropriate error tuple when asked to open a BEAM file without debug information but with a moduledoc(false) attribute.

    Own Id: OTP-20163
    Related Id(s): GH-11152, PR-11168

Full runtime dependencies of tools-4.2.1

compiler-8.5, crypto-5.9, erts-15.0, kernel-10.0, public_key-1.21, runtime_tools-2.1, stdlib-6.0

Thanks to

John Downey, Jonatan Männchen


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [erlang](https://github.com/erlang/otp) | minor | `29.0.1` → `29.1.1` | --- ### Release Notes <details> <summary>erlang/otp (erlang)</summary> ### [`v29.1.1`](https://github.com/erlang/otp/releases/tag/OTP-29.1.1): OTP 29.1.1 [Compare Source](https://github.com/erlang/otp/compare/OTP-29.1...OTP-29.1.1) ``` Patch Package: OTP 29.1.1 Git Tag: OTP-29.1.1 Date: 2026-09-22 Trouble Report Id: OTP-20272, OTP-20287, OTP-20355, OTP-20371, OTP-20386, OTP-20388, OTP-20390, OTP-20393 Seq num: CVE-2026-65634, CVE-2026-68956, CVE-2026-89422, ERIERL-1355, ERIERL-1363, GH-11586, GH-11619, GH-SA-qhcm-px9c-rvfh, PR-11523, PR-11559, PR-11616, PR-11630, PR-11638, PR-11641, PR-11651, PR-11655 System: OTP Release: 29 Application: asn1-5.5.2, compiler-10.0.6, public_key-1.21.7, ssh-6.0.6, ssl-11.7.7 Predecessor: OTP 29.1 ``` Check out the git tag OTP-29.1.1, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp\_patch\_apply' tool. For information on install requirements, see descriptions for each application version below. ### POTENTIAL INCOMPATIBILITIES - Fixed a vulnerability where the `max_channels` daemon option was not enforced for session channels without an active subsystem, allowing a remote authenticated user to open an infinite number of channels and exhaust server resources despite the configured limit. The default value of the max\_channels daemon option has been changed from infinity to 256. Deployments requiring more than 256 simultaneous channels per connection can restore the previous behavior by setting `{max_channels, infinity}`. The default value of the max\_sessions daemon option has been changed from infinity to 1024. Deployments requiring more concurrent SSH connections can restore the previous behavior by setting `{max_sessions, infinity}`. Own Id: OTP-20287\ Application(s): ssh\ Related Id(s): [GH-SA-qhcm-px9c-rvfh], [PR-11523], [CVE-2026-68956] ### asn1-5.5.2 The asn1-5.5.2 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed a denial-of-service attack in asn1, where abnormally large OID components (arcs) could cause resource exhaustion. Own Id: OTP-20272\ Related Id(s): [PR-11655], [CVE-2026-65634] - The JER backend will no longer break certain values (true, false, null) when they are typed as ENUMERATED, they will now be encoded as strings as required by the standard. Own Id: OTP-20355\ Related Id(s): ERIERL-1355, [PR-11559] > #### Full runtime dependencies of asn1-5.5.2 > > erts-14.0, kernel-9.0, stdlib-5.0 ### compiler-10.0.6 The compiler-10.0.6 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Certain uses of funs could crash the compiler. For example: ``` f() -> F = fun Fn(0) -> 0; Fn(N) -> Fn(N - 1) end, [F(X) || X <- [1, 2]]. ``` This has been corrected. Own Id: OTP-20386\ Related Id(s): [GH-11619], [PR-11638] > #### Full runtime dependencies of compiler-10.0.6 > > crypto-5.1, erts-13.0, kernel-8.4, stdlib-8.0 ### public\_key-1.21.7 The public\_key-1.21.7 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Handle that policy qualifiers are optional. Own Id: OTP-20393\ Related Id(s): [PR-11630] > #### Full runtime dependencies of public\_key-1.21.7 > > asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0 ### ssh-6.0.6 The ssh-6.0.6 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed a vulnerability where the `max_channels` daemon option was not enforced for session channels without an active subsystem, allowing a remote authenticated user to open an infinite number of channels and exhaust server resources despite the configured limit. The default value of the max\_channels daemon option has been changed from infinity to 256. Deployments requiring more than 256 simultaneous channels per connection can restore the previous behavior by setting `{max_channels, infinity}`. The default value of the max\_sessions daemon option has been changed from infinity to 1024. Deployments requiring more concurrent SSH connections can restore the previous behavior by setting `{max_sessions, infinity}`. Own Id: OTP-20287\ Related Id(s): [GH-SA-qhcm-px9c-rvfh], [PR-11523], [CVE-2026-68956] \*\*\* POTENTIAL INCOMPATIBILITY \*\*\* - The SSH daemon no longer rejects a `subsystem` request that is preceded by `env` or `pty-req` request on the same channel. Own Id: OTP-20371\ Related Id(s): ERIERL-1363, [GH-11586], [PR-11616] > #### Full runtime dependencies of ssh-6.0.6 > > crypto-5.7, erts-14.0, kernel-10.3, public\_key-1.6.1, runtime\_tools-1.15.1, stdlib-8.0 ### ssl-11.7.7 Note! The ssl-11.7.7 application *cannot* be applied independently of other applications on an arbitrary OTP 29 installation. ``` On a full OTP 29 installation, also the following runtime dependency has to be satisfied: -- public_key-1.21.1 (first satisfied in OTP 29.0.1) ``` #### Fixed Bugs and Malfunctions - Reject unsolicited TLS-1.3 pre\_shared\_key in client. Own Id: OTP-20388\ Related Id(s): [PR-11641], [CVE-2026-89422] - Security and robustness hardening returning RFC mandated alert reasons, narrowing/correcting length checks. Correct signature algorithm handling that slightly mixed up signature algorithms and signature algorithms cert in TLS-1.2. Add missing TLS-1.3 Brainpool groups support. (Not relevant in 27 patch) Enhanced/corrected documentation and spec errors/deviations. Own Id: OTP-20390\ Related Id(s): [PR-11651] > #### Full runtime dependencies of ssl-11.7.7 > > crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public\_key-1.21.1, runtime\_tools-1.15.1, stdlib-7.0 ### Thanks to Alan Duffield [cve-2026-65634]: https://nvd.nist.gov/vuln/detail/CVE-2026-65634 [cve-2026-68956]: https://nvd.nist.gov/vuln/detail/CVE-2026-68956 [cve-2026-89422]: https://nvd.nist.gov/vuln/detail/CVE-2026-89422 [gh-11586]: https://github.com/erlang/otp/issues/11586 [gh-11619]: https://github.com/erlang/otp/issues/11619 [gh-sa-qhcm-px9c-rvfh]: https://github.com/erlang/otp/issues/SA-qhcm-px9c-rvfh [pr-11523]: https://github.com/erlang/otp/pull/11523 [pr-11559]: https://github.com/erlang/otp/pull/11559 [pr-11616]: https://github.com/erlang/otp/pull/11616 [pr-11630]: https://github.com/erlang/otp/pull/11630 [pr-11638]: https://github.com/erlang/otp/pull/11638 [pr-11641]: https://github.com/erlang/otp/pull/11641 [pr-11651]: https://github.com/erlang/otp/pull/11651 [pr-11655]: https://github.com/erlang/otp/pull/11655 ### [`v29.1`](https://github.com/erlang/otp/releases/tag/OTP-29.1): OTP 29.1 [Compare Source](https://github.com/erlang/otp/compare/OTP-29.0.6...OTP-29.1) ``` Patch Package: OTP 29.1 Git Tag: OTP-29.1 Date: 2026-09-16 Trouble Report Id: OTP-19631, OTP-20118, OTP-20131, OTP-20145, OTP-20152, OTP-20158, OTP-20169, OTP-20175, OTP-20177, OTP-20180, OTP-20187, OTP-20188, OTP-20189, OTP-20209, OTP-20211, OTP-20213, OTP-20218, OTP-20228, OTP-20235, OTP-20236, OTP-20238, OTP-20246, OTP-20249, OTP-20254, OTP-20255, OTP-20256, OTP-20262, OTP-20265, OTP-20267, OTP-20276, OTP-20277, OTP-20280, OTP-20290, OTP-20291, OTP-20292, OTP-20293, OTP-20295, OTP-20297, OTP-20298, OTP-20303, OTP-20304, OTP-20305, OTP-20309, OTP-20316, OTP-20317, OTP-20318, OTP-20320, OTP-20322, OTP-20326, OTP-20327, OTP-20328, OTP-20331, OTP-20335, OTP-20338, OTP-20339, OTP-20352, OTP-20354, OTP-20356, OTP-20358, OTP-20362, OTP-20364, OTP-20365, OTP-20367, OTP-20373, OTP-20374 Seq num: ERIERL-1356, GH-10879, GH-10968, GH-11093, GH-11119, GH-11155, GH-11248, GH-11308, GH-11338, GH-11344, GH-11349, GH-11351, GH-11352, GH-11360, GH-11366, GH-11367, GH-11397, GH-11398, GH-11401, GH-11406, GH-11413, GH-11414, GH-11423, GH-11472, GH-11534, GH-4417, GH-7862, GH-9302, OTP-20102, PR-10297, PR-11074, PR-11096, PR-11097, PR-11115, PR-11128, PR-11129, PR-11130, PR-11133, PR-11137, PR-11144, PR-11159, PR-11165, PR-11167, PR-11170, PR-11196, PR-11203, PR-11216, PR-11226, PR-11249, PR-11260, PR-11274, PR-11284, PR-11300, PR-11313, PR-11316, PR-11324, PR-11335, PR-11345, PR-11356, PR-11359, PR-11361, PR-11363, PR-11375, PR-11376, PR-11378, PR-11379, PR-11388, PR-11390, PR-11391, PR-11396, PR-11410, PR-11422, PR-11424, PR-11426, PR-11438, PR-11440, PR-11442, PR-11444, PR-11446, PR-11447, PR-11460, PR-11466, PR-11477, PR-11501, PR-11505, PR-11507, PR-11530, PR-11552, PR-11556, PR-11563, PR-11566, PR-11567, PR-11570, PR-11574, PR-11600 System: OTP Release: 29 Application: asn1-5.5.1, common_test-1.31.2, compiler-10.0.5, crypto-5.10, dialyzer-6.0.3, erts-17.1, inets-9.8, kernel-11.0.4, mnesia-4.27, odbc-2.17.1, public_key-1.21.6, runtime_tools-2.5, ssl-11.7.6, stdlib-8.1, syntax_tools-4.1.1, tools-4.2.3, wx-2.7 Predecessor: OTP 29.0.6 ``` Check out the git tag OTP-29.1, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp\_patch\_apply' tool. For information on install requirements, see descriptions for each application version below. ### POTENTIAL INCOMPATIBILITIES - When `beam_lib` returns an error tuple, the filename in the information tuple is now a list of characters instead of an atom. Example: ``` 1> beam_lib:chunks(code:which(lists), ["nope"]). {error,beam_lib, {missing_chunk,".../git/otp/lib/stdlib/ebin/lists.beam", "nope"}} ``` The reason for this change is that a long file name is not guaranteed to fit in an atom. Applications or tools that do deep inspection of the `beam_lib` errors (not recommended) will need to be updated. Own Id: OTP-20118\ Application(s): stdlib\ Related Id(s): [PR-11167] ### OTP-29.1 #### Improvements and New Features - A new [`versions`] module has been added to the `runtime_tools` application containing functions for, e.g., comparing, versions that adhere to the [OTP Versions Scheme]. The documentation of the [OTP Versions Scheme] has also been improved. Own Id: OTP-20352\ Related Id(s): [PR-11556], [PR-11600] ### asn1-5.5.1 The asn1-5.5.1 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - The modern representation of BITSTRINGs is now always supported for encoding, regardless of any legacy options given. The JER backend would not support the modern representation when any legacy option was given. Own Id: OTP-20145\ Related Id(s): [PR-11097] - The `make clean` command did not remove all generated `.erl` files. Own Id: OTP-20295\ Related Id(s): [PR-11375] > #### Full runtime dependencies of asn1-5.5.1 > > erts-14.0, kernel-9.0, stdlib-5.0 ### common\_test-1.31.2 The common\_test-1.31.2 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - The internal `cte_track` event handler now correctly displays the suite name for suites without an `init_per_suite/1` callback. Own Id: OTP-20316\ Related Id(s): [PR-11501] > #### Full runtime dependencies of common\_test-1.31.2 > > compiler-10.0, crypto-4.5, debugger-4.1, erts-7.0, ftp-1.0, inets-6.0, kernel-11.0, observer-2.1, runtime\_tools-1.8.16, sasl-2.5, snmp-5.1.2, ssh-4.0, stdlib-8.0, syntax\_tools-1.7, tools-3.2, xmerl-1.3.8 ### compiler-10.0.5 The compiler-10.0.5 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed a native record crash in the `sys_core_fold` compiler pass. Own Id: OTP-20254\ Related Id(s): [GH-11351], [PR-11359] - The compiler could crash when compiling a map comprehension. Own Id: OTP-20255\ Related Id(s): [GH-11352], [PR-11363] - Fixed a crash when the key pattern in a map comprehension was a bitstring. Own Id: OTP-20262\ Related Id(s): [GH-11367], [PR-11379] - Fixed an issue that could crash the compiler when compiling comprehensions with the `compr_assign` feature enabled. Own Id: OTP-20267\ Related Id(s): [GH-11366], [PR-11390] - Code that called `erlang:0()` inside a fun could crash the compiler. Own Id: OTP-20280\ Related Id(s): [GH-11414], [PR-11424] - Fixed an internal error when `lists:keyfind/3` is called with an argument that exceeds system limits. Own Id: OTP-20291\ Related Id(s): [GH-11413], [PR-11444] - An incorrect `useless_building` warning has been eliminated. Own Id: OTP-20304\ Related Id(s): [GH-11472], [PR-11477] - In rare circumstances, the type analysis pass of the compiler could run for many minutes. Own Id: OTP-20365\ Related Id(s): [GH-11534], [PR-11566] > #### Full runtime dependencies of compiler-10.0.5 > > crypto-5.1, erts-13.0, kernel-8.4, stdlib-8.0 ### crypto-5.10 The crypto-5.10 application can be applied independently of other applications on a full OTP 29 installation. #### Improvements and New Features - The documentation of the `crypto` module now contains runnable examples for most functions. The examples are verified by the crypto test suite, so they always match actual behavior. Own Id: OTP-20373\ Related Id(s): [PR-11170] > #### Full runtime dependencies of crypto-5.10 > > erts-9.0, kernel-6.0, stdlib-3.9 ### dialyzer-6.0.3 The dialyzer-6.0.3 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed Dialyzer crash when overriding built-in types. Own Id: OTP-19631\ Related Id(s): [GH-11093], [PR-11096] - Typer crashed when multiple functions were written in the same line. For example: ``` -module(m). f() -> ok. g() -> ok. ``` Own Id: OTP-20297\ Related Id(s): [PR-11466] > #### Full runtime dependencies of dialyzer-6.0.3 > > compiler-10.0, erts-12.0, kernel-8.0, stdlib-5.0, syntax\_tools-2.0 ### erts-17.1 The erts-17.1 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed bug in `ets:member/2` for `set`, `bag` and `duplicate_bag`. The bug could (maybe) lead to `ets:member` spuriously returning false for a value which is actually a member for a table that faces high insert load. Own Id: OTP-20152\ Related Id(s): [PR-11115] - Fixed crashing bug caused by race between timer creating process and suspending receiver of the timer. Only seen to cause crash one time by extremely provoking test case. Bug exists only since OTP 29.0. Own Id: OTP-20175\ Related Id(s): [PR-11196] - Fixed bug in `enif_realloc_binary` when called with a read-only binary. Instead of returning false at out-of-memory failure, it returned true and did nothing. Own Id: OTP-20187\ Related Id(s): [PR-11133] - Fixed alternate signal stack sizing on musl (Alpine) running on CPUs whose Linux kernel reports large signal frames (AVX-512/AMX). It caused emulator to abort during startup with "Failed to set alternate signal stack". Own Id: OTP-20213\ Related Id(s): [GH-11248], [PR-11249] - For `socket:recvmmsg/6`, the buffer length was not handled correctly when the OS network stack truncated the received message, so garbage data with incorrect length could be delivered to the calling process. This bug has been corrected. Own Id: OTP-20246\ Related Id(s): [PR-11335] - `binary_to_term/1` will now reject an external native record with duplicated fields. Own Id: OTP-20276\ Related Id(s): [GH-11398], [PR-11410] - Fixed a crash upon starting the emulator on systems with a very large minimum signal stack size. Own Id: OTP-20292\ Related Id(s): [GH-11349], [PR-11376] - Fixed lock order violation during crash dump due to export table exhaustion. Only problem for debug emulator. Own Id: OTP-20305\ Related Id(s): [PR-11460] - Fixed rounding errors when converting large integers to floating point numbers, explicitly with `float/1` or implicitly in arithmetic such as `1.0 * N`. Integers with absolute values larger than 64 bits that could not be represented exactly as a float could be rounded to the second nearest float instead of the nearest. For example, `float(428654966685883400000)` returned `4.2865496668588343e20` instead of the correct `4.286549666858834e20`, which is what `binary_to_float/1` returns for the same number. Own Id: OTP-20317\ Related Id(s): [PR-11391] - An error check in `prim_inet` has been fixed. This manifested itself as `file:sendfile/*` sometimes crashing instead of returning an error when the remote end closes the socket during initialization. Own Id: OTP-20356\ Related Id(s): [PR-11438] #### Improvements and New Features - Fairness of code permission locks have been improved to avoid long latencies for code loading and trace operations. Own Id: OTP-20188\ Related Id(s): [PR-11144] - The BIFs that convert strings to integers (for example [`binary_to_integer/1`]) are now much faster for huge input strings. On a modern computer, even a string with more than a million decimal digits should finish in less than a second. The `div` and `rem` operators are now also much faster for large operands. Own Id: OTP-20209\ Related Id(s): [PR-11074], [PR-11324] - Arithmetic operations on large integers will now increase the reduction count for the process, causing context switches to occur more frequently when doing arithmetic on large integers. Own Id: OTP-20211\ Related Id(s): [PR-11274] > #### Full runtime dependencies of erts-17.1 > > kernel-9.0, sasl-3.3, stdlib-4.1 ### inets-9.8 The inets-9.8 application can be applied independently of other applications on a full OTP 29 installation. #### Improvements and New Features - OPTIONS is now accepted for HTTP/1.x requests and routed through the normal module pipeline like other standard methods. Requests that no module handles still receive a 501 (Not Implemented) response, so behavior is unchanged for deployments that do not add explicit OPTIONS handling. Own Id: OTP-20249\ Related Id(s): [GH-11119], [PR-11316] > #### Full runtime dependencies of inets-9.8 > > erts-14.0, kernel-9.0, mnesia-4.12, public\_key-1.13, runtime\_tools-1.8.14, ssl-9.0, stdlib-5.0, stdlib-6.0 ### kernel-11.0.4 The kernel-11.0.4 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed incorrect TOS format when using `gen_udp` with the `socket` backend. Own Id: OTP-20131\ Related Id(s): [GH-10968], OTP-20102 - Decoding of names in `inet_res` has been tightened to not allow names longer than 255 octets, as according to RFC 1035. Decoding has also been made more strict by only allowing compression pointers to lower positions in the message. A few bugs when decoding malformed truncated DNS messages have also been fixed, as well as handling broken UTF-8 content in NAPTR RR:s regular expressions field. Own Id: OTP-20228\ Related Id(s): [PR-11300] - When using the `socket` backend in `gen_tcp`, the default value for the `read_ahead` option was incorrect and has been corrected, according the documentation, to be `true`. Own Id: OTP-20238\ Related Id(s): [PR-11284] - A field in `net_kernel`'s internal state was not cleaned up in some cases for failed connections could cause the state to grow indefinitely over time. This has now been fixed. Own Id: OTP-20265\ Related Id(s): [GH-11308], [PR-11388] - Fixed `pg:which_groups/1` to not include empty groups where all members have leaved. Bug existed since OTP 29.0. Own Id: OTP-20303\ Related Id(s): [GH-11360], [PR-11361] > #### Full runtime dependencies of kernel-11.0.4 > > crypto-5.8, erts-17.0, sasl-3.0, stdlib-8.0 ### mnesia-4.27 The mnesia-4.27 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed `mnesia:force_load_table/1` getting stuck when the remote node becomes unreachable during table loading. When a network loader is aborted due to sender node going down and a user has forced a table load, we now retry loading from disc instead. Additionally, for disc\_only\_copies tables, the process actually loading the table is the dets server process, not the mnesia loader, so it would not receive the abort notification and would hang indefinitely. Now it correctly receives the notification and aborts table loading. Own Id: OTP-20256\ Related Id(s): [GH-11344], [PR-11426] - Fixed incorrect results from `mnesia:select_reverse/2,3` on `ordered_set` tables inside a transaction that had already written to or deleted from the same table. Deleted records could reappear, updated records could appear twice, and the descending order was not preserved. Own Id: OTP-20364\ Related Id(s): [PR-11563] #### Improvements and New Features - The documentation of the `mnesia` module now contains runnable examples for most functions. The examples are verified by the mnesia test suite, so they always match actual behavior. Own Id: OTP-20374\ Related Id(s): [PR-11216] > #### Full runtime dependencies of mnesia-4.27 > > erts-9.0, kernel-5.3, stdlib-5.0 ### odbc-2.17.1 The odbc-2.17.1 application can be applied independently of other applications on a full OTP 29 installation. #### Improvements and New Features - Added the `max_long_column_size` option to limit buffer allocation size preventing memory exhaustion. Own Id: OTP-20328\ Related Id(s): [GH-9302], [PR-10297] > #### Full runtime dependencies of odbc-2.17.1 > > erts-6.0, kernel-3.0, stdlib-2.0 ### public\_key-1.21.6 The public\_key-1.21.6 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Added missing `no_cacerts_found` clauses so that the intended `{failed_load_cacerts, no_cacerts_found}` error is raised and formatted properly. Own Id: OTP-20318\ Related Id(s): [PR-11378] - Align moduli and pubkey\_moduli.hrl to state on OTP-28 and newer. Own Id: OTP-20367\ Related Id(s): [PR-11574] #### Improvements and New Features - Worked around domain component using wrong ASN-1 `PrintableString` encoding instead of `IA5String` encoding. Own Id: OTP-20338\ Related Id(s): [GH-10879], [PR-11226] - ASN.1 files are now compiled sequentially to guarantee reproducible builds. Own Id: OTP-20362\ Related Id(s): [GH-4417], [PR-11396] > #### Full runtime dependencies of public\_key-1.21.6 > > asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0 ### runtime\_tools-2.5 The runtime\_tools-2.5 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed bug if a process that called `dbg:session/2` exits before `dbg:session_destroy/1` is called. An error report was logged and any trace messages lost and not delivered. Own Id: OTP-20218\ Related Id(s): [PR-11260] #### Improvements and New Features - A new [`versions`] module has been added to the `runtime_tools` application containing functions for, e.g., comparing, versions that adhere to the [OTP Versions Scheme]. The documentation of the [OTP Versions Scheme] has also been improved. Own Id: OTP-20352\ Related Id(s): [PR-11556], [PR-11600] > #### Full runtime dependencies of runtime\_tools-2.5 > > erts-16.0, kernel-10.0, mnesia-4.12, stdlib-6.0 ### ssl-11.7.6 Note! The ssl-11.7.6 application *cannot* be applied independently of other applications on an arbitrary OTP 29 installation. ``` On a full OTP 29 installation, also the following runtime dependency has to be satisfied: -- public_key-1.21.1 (first satisfied in OTP 29.0.1) ``` #### Fixed Bugs and Malfunctions - Undecodable `certificate_authorities` names are now skipped, as they are just a hint. Own Id: OTP-20327\ Related Id(s): [GH-11338], [PR-11356] - Corrected generated keylog information generated from the `keylog_hs` option in the corner case that it was invoked after the client had reached its connection state, but the server closed the connection before it reached its connection state. Own Id: OTP-20358\ Related Id(s): ERIERL-1356, [PR-11570] #### Improvements and New Features - Added TLS-1.3 `selected_group` to `ssl:connection_information/2`. Own Id: OTP-20326\ Related Id(s): [PR-11440] - The ECDHE-PSK Chacha20-Poly1305 cipher suites are now supported. This is relevant for TLS-1.2 (and lower). Own Id: OTP-20331\ Related Id(s): [PR-11345] > #### Full runtime dependencies of ssl-11.7.6 > > crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public\_key-1.21.1, runtime\_tools-1.15.1, stdlib-7.0 ### stdlib-8.1 The stdlib-8.1 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - When `beam_lib` returns an error tuple, the filename in the information tuple is now a list of characters instead of an atom. Example: ``` 1> beam_lib:chunks(code:which(lists), ["nope"]). {error,beam_lib, {missing_chunk,".../git/otp/lib/stdlib/ebin/lists.beam", "nope"}} ``` The reason for this change is that a long file name is not guaranteed to fit in an atom. Applications or tools that do deep inspection of the `beam_lib` errors (not recommended) will need to be updated. Own Id: OTP-20118\ Related Id(s): [PR-11167] \*\*\* POTENTIAL INCOMPATIBILITY \*\*\* - The default seed in the `rand` module has been improved to spread out its entropy over all three seed words. This avoids identical first random numbers from two successive seeds on machines with low system time resolution. Own Id: OTP-20158\ Related Id(s): [PR-11165] - Fixed `unicode:characters_to_binary/2` to handle incomplete utf-32 sequences without crashing. Also fixed a performance regression in `unicode:characters_to_nfkd_list/1`. Own Id: OTP-20169\ Related Id(s): [PR-11130] - The `array` module has been improved. `array:slice/3` now raises `badarg` for negative lengths. The performance of `array:mapfoldl/3` and `array:sparse_mapfoldl/3` has been improved. The documentation has been clarified regarding array growth/shrink behavior and how `concat/1,2` handles mixed arrays. Own Id: OTP-20177\ Related Id(s): [PR-11159] - Added more checks in the linter for badly formed `{Name,Arity}` attributes Own Id: OTP-20277\ Related Id(s): [GH-11397], [PR-11422] - Fixed return value of `zip:zip_get/2`. When a file was extracted to a directory, the function returned a map instead of a file name. Own Id: OTP-20298\ Related Id(s): [PR-11313] - When `compr_assign` is enabled, the linter will correctly check for unbounded variables after block expressions in comprehensions. Own Id: OTP-20309\ Related Id(s): [GH-11406], [PR-11567] - When compiling a module with a triple-quoted string with escape sequences and a chunk boundary happened to fall just after an escape character, that character was not passed to the reentrancy continuation, so the scanner interpreted the following characters as not an escape sequence. This bug has now been fixed. Own Id: OTP-20320\ Related Id(s): [GH-11423], [PR-11505] - Fixed some errors in examples in the documentation for the [`string`] and [`uri_string`] modules. Own Id: OTP-20322\ Related Id(s): [PR-11446] - Linter will emit better error messages when a behaviour attribute has a bad module name. Own Id: OTP-20354\ Related Id(s): [GH-11401], [PR-11552] #### Improvements and New Features - `uri_string:parse/1` now reports the actual offending character in error tuples instead of reporting a misleading cascade-failure position. Previously, when parsing a URI containing an invalid character (such as `|` or non-ASCII characters like `ö`), the error tuple would point to the `:` character — the position where the parser's final backtracking attempt failed — rather than the character that actually violated the URI grammar. For example, `uri_string:parse("http://localhost/A|B")` returned `{error,invalid_uri,":"}` instead of the more helpful `{error,invalid_uri,"|"}` Own Id: OTP-20235\ Related Id(s): [GH-7862], [PR-11129] - Fixed a guard precedence bug in `uri_string:compose_query/2` that caused inconsistent error handling depending on the encoding option. When `compose_query/2` was called with invalid input (e.g. an atom instead of a string) and `{encoding, unicode}`, it would crash with `** exception error: bad argument` instead of returning the expected `{error, invalid_input, Term}` tuple. The same call with `{encoding, utf8}` correctly returned the error tuple. Both encoding options now consistently return `{error, invalid_input, Term}` for invalid input. Own Id: OTP-20236\ Related Id(s): [PR-11128] > #### Full runtime dependencies of stdlib-8.1 > > compiler-5.0, crypto-4.5, erts-16.0.3, kernel-11.0, sasl-3.0, syntax\_tools-3.2.1 ### syntax\_tools-4.1.1 The syntax\_tools-4.1.1 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed exception when the epp\_dodger AST contains macro-named record. Own Id: OTP-20180\ Related Id(s): [GH-11155], [PR-11203] - Any caller who passed a single syntax tree that was not a form\_list (e.g. `erl_recomment:recomment_forms(erl_syntax:atom(foo), Cs)` or any expression/function tree) would get a hard crash instead of the documented result. This issue has been fixed. Own Id: OTP-20290\ Related Id(s): [PR-11442] > #### Full runtime dependencies of syntax\_tools-4.1.1 > > compiler-9.0, erts-16.0, kernel-10.3, stdlib-8.0 ### tools-4.2.3 The tools-4.2.3 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - The `tags.erl` module is used to generate `TAGS` files for Emacs. There was a case where single quote items starting in position 0 would crash the scanner. This use case can potentially happen in docstrings, although not too common. This fix makes the scanner to handle such cases instead of crashing. Own Id: OTP-20293\ Related Id(s): [PR-11447] - Updated the Emacs skeleton to reflect latest `format_status` callback handling. Own Id: OTP-20339\ Related Id(s): [PR-11507] > #### Full runtime dependencies of tools-4.2.3 > > compiler-8.5, crypto-5.9, erts-15.0, kernel-10.0, public\_key-1.21, runtime\_tools-2.1, stdlib-6.0 ### wx-2.7 The wx-2.7 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - A large set of correctness and robustness fixes were applied across the `wx` application, addressing issues found by static analysis of both the Erlang and C/C++ sources. Own Id: OTP-20335\ Related Id(s): [PR-11530] #### Improvements and New Features - Removed configure checks that prevented cross compilation of wx. Note that cross compilation is not tested and may require manual configuration. Own Id: OTP-20189\ Related Id(s): [PR-11137] > #### Full runtime dependencies of wx-2.7 > > erts-12.0, kernel-8.0, stdlib-5.0 ### Thanks to Alois Vitasek, Anton Thomasson, ausimian, Bernhard M. Wiedemann, Cole Christensen, Dmitri Vereshchagin, Dmytro Lytovchenko, Eric Meadows-Jönsson, haoxian, Jianbo He, João Henrique Ferreira de Freitas, Johan Bevemyr, John Downey, Jonatan Männchen, Julian Doherty, kagetora66, k-patrik, Louis Pilfold, Lukasz Samson, Luke Bakken, Maria Scott, Mikael Pettersson, Paul Guyot, Renato Ceolin, ruslandoga, Scott Wiggins, Stanislav Yaglo, Thomas Arts, Thomas Cioppettini, Zeke Dou, zmstone [gh-10879]: https://github.com/erlang/otp/issues/10879 [gh-10968]: https://github.com/erlang/otp/issues/10968 [gh-11093]: https://github.com/erlang/otp/issues/11093 [gh-11119]: https://github.com/erlang/otp/issues/11119 [gh-11155]: https://github.com/erlang/otp/issues/11155 [gh-11248]: https://github.com/erlang/otp/issues/11248 [gh-11308]: https://github.com/erlang/otp/issues/11308 [gh-11338]: https://github.com/erlang/otp/issues/11338 [gh-11344]: https://github.com/erlang/otp/issues/11344 [gh-11349]: https://github.com/erlang/otp/issues/11349 [gh-11351]: https://github.com/erlang/otp/issues/11351 [gh-11352]: https://github.com/erlang/otp/issues/11352 [gh-11360]: https://github.com/erlang/otp/issues/11360 [gh-11366]: https://github.com/erlang/otp/issues/11366 [gh-11367]: https://github.com/erlang/otp/issues/11367 [gh-11397]: https://github.com/erlang/otp/issues/11397 [gh-11398]: https://github.com/erlang/otp/issues/11398 [gh-11401]: https://github.com/erlang/otp/issues/11401 [gh-11406]: https://github.com/erlang/otp/issues/11406 [gh-11413]: https://github.com/erlang/otp/issues/11413 [gh-11414]: https://github.com/erlang/otp/issues/11414 [gh-11423]: https://github.com/erlang/otp/issues/11423 [gh-11472]: https://github.com/erlang/otp/issues/11472 [gh-11534]: https://github.com/erlang/otp/issues/11534 [gh-4417]: https://github.com/erlang/otp/issues/4417 [gh-7862]: https://github.com/erlang/otp/issues/7862 [gh-9302]: https://github.com/erlang/otp/issues/9302 [otp versions scheme]: https://erlang.org/doc/system/versions.html#version-scheme [pr-10297]: https://github.com/erlang/otp/pull/10297 [pr-11074]: https://github.com/erlang/otp/pull/11074 [pr-11096]: https://github.com/erlang/otp/pull/11096 [pr-11097]: https://github.com/erlang/otp/pull/11097 [pr-11115]: https://github.com/erlang/otp/pull/11115 [pr-11128]: https://github.com/erlang/otp/pull/11128 [pr-11129]: https://github.com/erlang/otp/pull/11129 [pr-11130]: https://github.com/erlang/otp/pull/11130 [pr-11133]: https://github.com/erlang/otp/pull/11133 [pr-11137]: https://github.com/erlang/otp/pull/11137 [pr-11144]: https://github.com/erlang/otp/pull/11144 [pr-11159]: https://github.com/erlang/otp/pull/11159 [pr-11165]: https://github.com/erlang/otp/pull/11165 [pr-11167]: https://github.com/erlang/otp/pull/11167 [pr-11170]: https://github.com/erlang/otp/pull/11170 [pr-11196]: https://github.com/erlang/otp/pull/11196 [pr-11203]: https://github.com/erlang/otp/pull/11203 [pr-11216]: https://github.com/erlang/otp/pull/11216 [pr-11226]: https://github.com/erlang/otp/pull/11226 [pr-11249]: https://github.com/erlang/otp/pull/11249 [pr-11260]: https://github.com/erlang/otp/pull/11260 [pr-11274]: https://github.com/erlang/otp/pull/11274 [pr-11284]: https://github.com/erlang/otp/pull/11284 [pr-11300]: https://github.com/erlang/otp/pull/11300 [pr-11313]: https://github.com/erlang/otp/pull/11313 [pr-11316]: https://github.com/erlang/otp/pull/11316 [pr-11324]: https://github.com/erlang/otp/pull/11324 [pr-11335]: https://github.com/erlang/otp/pull/11335 [pr-11345]: https://github.com/erlang/otp/pull/11345 [pr-11356]: https://github.com/erlang/otp/pull/11356 [pr-11359]: https://github.com/erlang/otp/pull/11359 [pr-11361]: https://github.com/erlang/otp/pull/11361 [pr-11363]: https://github.com/erlang/otp/pull/11363 [pr-11375]: https://github.com/erlang/otp/pull/11375 [pr-11376]: https://github.com/erlang/otp/pull/11376 [pr-11378]: https://github.com/erlang/otp/pull/11378 [pr-11379]: https://github.com/erlang/otp/pull/11379 [pr-11388]: https://github.com/erlang/otp/pull/11388 [pr-11390]: https://github.com/erlang/otp/pull/11390 [pr-11391]: https://github.com/erlang/otp/pull/11391 [pr-11396]: https://github.com/erlang/otp/pull/11396 [pr-11410]: https://github.com/erlang/otp/pull/11410 [pr-11422]: https://github.com/erlang/otp/pull/11422 [pr-11424]: https://github.com/erlang/otp/pull/11424 [pr-11426]: https://github.com/erlang/otp/pull/11426 [pr-11438]: https://github.com/erlang/otp/pull/11438 [pr-11440]: https://github.com/erlang/otp/pull/11440 [pr-11442]: https://github.com/erlang/otp/pull/11442 [pr-11444]: https://github.com/erlang/otp/pull/11444 [pr-11446]: https://github.com/erlang/otp/pull/11446 [pr-11447]: https://github.com/erlang/otp/pull/11447 [pr-11460]: https://github.com/erlang/otp/pull/11460 [pr-11466]: https://github.com/erlang/otp/pull/11466 [pr-11477]: https://github.com/erlang/otp/pull/11477 [pr-11501]: https://github.com/erlang/otp/pull/11501 [pr-11505]: https://github.com/erlang/otp/pull/11505 [pr-11507]: https://github.com/erlang/otp/pull/11507 [pr-11530]: https://github.com/erlang/otp/pull/11530 [pr-11552]: https://github.com/erlang/otp/pull/11552 [pr-11556]: https://github.com/erlang/otp/pull/11556 [pr-11563]: https://github.com/erlang/otp/pull/11563 [pr-11566]: https://github.com/erlang/otp/pull/11566 [pr-11567]: https://github.com/erlang/otp/pull/11567 [pr-11570]: https://github.com/erlang/otp/pull/11570 [pr-11574]: https://github.com/erlang/otp/pull/11574 [pr-11600]: https://github.com/erlang/otp/pull/11600 [`binary_to_integer/1`]: https://www.erlang.org/doc/apps/erts/erlang.html#binary_to_integer/1 [`string`]: https://erlang.org/doc/man/string [`uri_string`]: https://erlang.org/doc/man/uri_string [`versions`]: https://erlang.org/doc/man/versions ### [`v29.0.6`](https://github.com/erlang/otp/releases/tag/OTP-29.0.6): OTP 29.0.6 [Compare Source](https://github.com/erlang/otp/compare/OTP-29.0.5...OTP-29.0.6) ``` Patch Package: OTP 29.0.6 Git Tag: OTP-29.0.6 Date: 2026-09-01 Trouble Report Id: OTP-20135, OTP-20234, OTP-20264, OTP-20268, OTP-20269, OTP-20270, OTP-20271, OTP-20274, OTP-20278, OTP-20279, OTP-20281, OTP-20282, OTP-20284, OTP-20286, OTP-20289, OTP-20296, OTP-20300, OTP-20301, OTP-20302, OTP-20306, OTP-20307, OTP-20308, OTP-20312, OTP-20319, OTP-20321, OTP-20324, OTP-20330, OTP-20333, OTP-20334, OTP-20342, OTP-20343, OTP-20344, OTP-20345, OTP-20346, OTP-20347, OTP-20350, OTP-20351 Seq num: CVE-2026-75538, ERIERL-1345, ERIERL-1354, GH-11052, GH-11240, GH-11278, GH-11380, GH-11404, GH-11416, GH-11419, GH-11494, GH-11511, PR-11298, PR-11325, PR-11358, PR-11417, PR-11425, PR-11428, PR-11429, PR-11437, PR-11463, PR-11464, PR-11470, PR-11478, PR-11481, PR-11485, PR-11492, PR-11503, PR-11509, PR-11513, PR-11517, PR-11521, PR-11533, PR-11538, PR-11539, PR-11540, PR-11541, PR-11542, PR-11543, PR-11544, PR-11545, PR-11546, PR-11547, PR-11548, PR-11553, PR-11554 System: OTP Release: 29 Application: compiler-10.0.4, crypto-5.9.3, eldap-1.3.1, erl_interface-5.8.2, erts-17.0.6, inets-9.7.2, megaco-4.9.2, mnesia-4.26.2, public_key-1.21.5, snmp-5.20.5, ssh-6.0.5, ssl-11.7.5, stdlib-8.0.4, tools-4.2.2 Predecessor: OTP 29.0.5 ``` Check out the git tag OTP-29.0.6, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp\_patch\_apply' tool. For information on install requirements, see descriptions for each application version below. ### compiler-10.0.4 The compiler-10.0.4 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - compiler: Fix bug in `beam_types:subtract/2` for bitstrings Own Id: OTP-20312\ Related Id(s): [GH-11494], [PR-11503] > #### Full runtime dependencies of compiler-10.0.4 > > crypto-5.1, erts-13.0, kernel-8.4, stdlib-8.0 ### crypto-5.9.3 The crypto-5.9.3 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed type mismatch between `ErlNifUInt64` and `uint64_t` in crypto NIF that caused incompatible-pointer warnings on macOS arm64 when passing DH parameters to OpenSSL. Own Id: OTP-20333\ Related Id(s): [GH-11511], [PR-11513] > #### Full runtime dependencies of crypto-5.9.3 > > erts-9.0, kernel-6.0, stdlib-3.9 ### eldap-1.3.1 The eldap-1.3.1 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - eldap referral URL parsing now rejects a port component longer than 5 digits instead of attempting to convert an arbitrarily large digit string to an integer. Own Id: OTP-20345\ Related Id(s): [PR-11538] [CVE-2026-70409] > #### Full runtime dependencies of eldap-1.3.1 > > asn1-3.0, erts-6.0, kernel-3.0, ssl-5.3.4, stdlib-3.4 ### erl\_interface-5.8.2 The erl\_interface-5.8.2 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - erl\_interface: Fix buffer leak and state corruption on `ei_x_buff` realloc failure Own Id: OTP-20324\ Related Id(s): [PR-11492] ### erts-17.0.6 The erts-17.0.6 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - No-suspend port command signals (i.e. port command signals sent using the `erlang:port_command/3` BIF or the `erlang:send/3` BIF with the `nosuspend` option) were not aborted properly in all scenarios which could leave the port queue in a busy state indefinitely. Also asynchronously sent no-suspend command signals (i.e, port command signals sent using the `erlang:send/3` BIF with the `nosuspend` option) could sometimes be delivered even though the port was busy. Own Id: OTP-20135\ Related Id(s): [GH-11052], [PR-11463] - erts: Fix missing exit\_status caused by SIGCHLD race Own Id: OTP-20274\ Related Id(s): [GH-11278], [PR-11298] - erts: Fix bug in `is_in_range` instruction for x86 JIT Own Id: OTP-20278\ Related Id(s): [GH-11419], [PR-11429] - Fixed bug in `binary_to_term` that could cause emulator crash for specific terms in specific process states (reductions left). Own Id: OTP-20281\ Related Id(s): [GH-11404], [PR-11425] - erts: Fix crash with `term_to_iovec/2` for large binary Own Id: OTP-20282\ Related Id(s): [PR-11428] - A distributed `priority` send larger than 32 KiB to a process alias caused the receiving runtime system to crash. Own Id: OTP-20286\ Related Id(s): [GH-11416], [PR-11417] - Priority message queue markers were sometimes installed in the message queue even when no priority messages could be received. As a result, the two markers had to be traversed unnecessarily when scanning the message queue, introducing a small but avoidable overhead. Own Id: OTP-20300\ Related Id(s): [PR-11485] - A monitor of `time_offset` co-created with a process alias (`monitor(time_offset, clock_service, [{alias, UnaliasOpt}])`) either crashed the runtime system or did not work. This bug was introduced in OTP 25.0. Own Id: OTP-20319\ Related Id(s): [PR-11509] - A process alias was erroneously created when a remote `spawn_request()` operation with a `{monitor, [{alias, explicit_unalias}]}` option failed with `noconnection` reason. Own Id: OTP-20330\ Related Id(s): [PR-11521] - A `gen_tcp` socket using the inet driver and `{packet,4}` had a bug if receiving a packet with size just below INT\_MAX. That packet size wrapped in size calculations and made the received data overwrite its allocation and trash allocator metadata and subsequent block(s), causing the VM to crash. This made it possible for anyone to remotely crash an Erlang node that used `{packet,4}` on a reachable socket. This bug has been corrected. Own Id: OTP-20334\ Related Id(s): [PR-11533], [CVE-2026-75538] > #### Full runtime dependencies of erts-17.0.6 > > kernel-9.0, sasl-3.3, stdlib-4.1 ### inets-9.7.2 The inets-9.7.2 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - The `dets` and `mnesia` `mod_auth` backends used a key that did not include the directory path, so all `require_user`/`require_group` records collapsed into one per-listener namespace. A user authorized for one protected directory could authenticate against any other protected directory served by the same listener. `{path, Directory}` is now included in the auth backend key, scoping records per directory as documented. Own Id: OTP-20264\ Related Id(s): [PR-11546] [CVE-2026-74994] - Requests specifying both `Transfer-Encoding` and `Content-Length` headers are now rejected with `400 Bad Request`, per RFC 9112 Section 6.3. Previously such requests could be used for CL.TE request-smuggling/desync attacks against reverse proxies in front of `httpd`. Own Id: OTP-20268\ Related Id(s): [PR-11547] [CVE-2026-73812] - `httpd` accepted the obsolete header line-folding syntax (RFC 9112 Section 5.2, a continuation line beginning with space/tab), silently treating the folded continuation as a separate header. This allowed CL.TE-style request smuggling when `httpd` was placed behind a folding-aware proxy. Such requests are now rejected with `400 Bad Request`. Own Id: OTP-20269\ Related Id(s): [PR-11544] [CVE-2026-66357] - A header such as `Content-Length : 6` (whitespace before the colon) was previously silently dropped, causing the content length to default to 0 and the body bytes to be misinterpreted as a pipelined request (CL.0 smuggling). Per RFC 7230 Section 3.2.4, such headers are now rejected with `400 Bad Request`. Own Id: OTP-20270\ Related Id(s): [PR-11545] [CVE-2026-73276] - A new httpd option `request_timeout` (default 60 seconds, renamed from the interim `max_body_read_timeout`) bounds the idle time between reads of a request body/message. The server now also sends `408 Request Timeout` when the `min_bytes_per_second` floor is hit, and `keep_alive_timeout` measurement was corrected so the timer is cancelled as soon as new data arrives rather than only after full header parsing; `keep_alive_timeout` and `request_timeout` now also accept `infinity` to disable the timeout. Own Id: OTP-20271\ Related Id(s): [PR-11543] [CVE-2026-71380] - `mod_auth`, `mod_security`, and `mod_get` compared resolved filesystem paths against configured protected-directory patterns without normalizing repeated slashes or filesystem case. On case-insensitive filesystems (macOS, Windows) or with repeated slashes, a request could resolve to a protected resource while evading the directory match. Paths are now canonicalized (slash-collapsed, and case-normalized when the filesystem is case-insensitive) before the authorization decision. Own Id: OTP-20279\ Related Id(s): [PR-11542] [CVE-2026-73270] [CVE-2026-66835] - A request with an invalid chunked transfer-encoding chunk size previously caused the httpd connection handler to hang indefinitely without requiring further input from the client. This leaked a process per request and could be used to exhaust server resources (denial of service). Invalid chunk sizes are now rejected immediately with an error response, and the connection is closed. Own Id: OTP-20306\ Related Id(s): [PR-11539] [CVE-2026-69664] - `max_body_size` was previously enforced only after a complete chunk had been received, allowing a single oversized chunk to be buffered in full before the limit was checked — undermining the memory-exhaustion protection the option is meant to provide. The limit is now enforced incrementally as chunk data arrives, rejecting the request as soon as the configured size is exceeded. Own Id: OTP-20307\ Related Id(s): [PR-11540] [CVE-2026-74835] - The documented default of 150 for the `max_clients` option was not applied by the implementation, allowing an unbounded number of concurrent clients to connect regardless of configuration. The default is now correctly enforced. Own Id: OTP-20308\ Related Id(s): [PR-11541] [CVE-2026-70399] - Fixed a bug where httpd failed to start when configured with {socket\_type, {ip\_comm, SockOpts}} and a fixed (non-zero) port. Own Id: OTP-20342\ Related Id(s): [PR-11548] - `httpc` now enforces a limit on the total size of response headers and response body, preventing unbounded memory allocation when connecting to a malicious or malfunctioning server. The new max\_header\_size and max\_body\_size request options can be used to override the default limit (10240 bytes for headers). Additionally, httpc now validates that the Content-Length header contains only digits before use, avoiding a crash on malformed responses. Own Id: OTP-20343\ Related Id(s): [PR-11538] [CVE-2026-55951] [CVE-2026-71562] > #### Full runtime dependencies of inets-9.7.2 > > erts-14.0, kernel-9.0, mnesia-4.12, public\_key-1.13, runtime\_tools-1.8.14, ssl-9.0, stdlib-5.0, stdlib-6.0 ### megaco-4.9.2 The megaco-4.9.2 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Numeric fields in megaco text-encoded messages are now validated for digit-string length before integer conversion, improving robustness of the text decoder. Per-field digit limits based on the H.248.1 ASN.1 type constraints are enforced (e.g., 10 digits for UINT32, 2 digits for timer values), along with a 100 KB overall message size cap at the scanner entry point. The binary (BER/PER) codec is not affected. Own Id: OTP-20234\ Related Id(s): [PR-11325] > #### Full runtime dependencies of megaco-4.9.2 > > asn1-3.0, debugger-4.0, erts-12.0, et-1.5, kernel-8.0, runtime\_tools-1.8.14, stdlib-2.5 ### mnesia-4.26.2 The mnesia-4.26.2 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - A transaction iterating a table (first/1, last/1, next/2, prev/2, select, select\_reverse on non-ordered\_set) leaked a safe\_fixtable hold when the coordinator was killed by an external signal. The table remained fixed for the lifetime of the node, preventing space reclamation of deleted objects. Own Id: OTP-20347\ Related Id(s): [PR-11517] - Fixed a race condition where mnesia\_controller could crash if a table was deleted while `mnesia:set_master_nodes/2` was being processed. Own Id: OTP-20351\ Related Id(s): [PR-11554] > #### Full runtime dependencies of mnesia-4.26.2 > > erts-9.0, kernel-5.3, stdlib-5.0 ### public\_key-1.21.5 The public\_key-1.21.5 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Retain lost CommonName length relaxation. Own Id: OTP-20321\ Related Id(s): [GH-11240], [PR-11358] > #### Full runtime dependencies of public\_key-1.21.5 > > asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0 ### snmp-5.20.5 The snmp-5.20.5 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - The SNMP PDU decoder now bounds the byte length accepted for INTEGER, Counter32, Gauge32/Unsigned32, TimeTicks, and Counter64 values during decoding (4, 5, 5, 5, and 9 bytes respectively, matching the SMIv2 value ranges), instead of accepting an arbitrarily large byte string and converting it to an integer. Own Id: OTP-20346\ Related Id(s): [PR-11538] [CVE-2026-70405] > #### Full runtime dependencies of snmp-5.20.5 > > asn1-5.4, crypto-4.6, erts-12.0, kernel-8.0, mnesia-4.12, runtime\_tools-1.8.14, stdlib-5.0 ### ssh-6.0.5 The ssh-6.0.5 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed a bug where multiple subsystem requests could succeed on same ssh channel which is forbidden by RFC 4254 §6.5 Own Id: OTP-20284\ Related Id(s): [PR-11437] > #### Full runtime dependencies of ssh-6.0.5 > > crypto-5.7, erts-14.0, kernel-10.3, public\_key-1.6.1, runtime\_tools-1.15.1, stdlib-8.0 ### ssl-11.7.5 Note! The ssl-11.7.5 application *cannot* be applied independently of other applications on an arbitrary OTP 29 installation. ``` On a full OTP 29 installation, also the following runtime dependency has to be satisfied: -- public_key-1.21.1 (first satisfied in OTP 29.0.1) ``` #### Fixed Bugs and Malfunctions - Debugging keylog\_hs callback used for logging handshake secrets on failed connections swapped the argument order in logging function confusing server and client side. The bug was introduced in OTP 28.5 Own Id: OTP-20350\ Related Id(s): ERIERL-1354, [PR-11553] #### Improvements and New Features - Hardening improvements of the ssl application. TLS distribution now defaults to TLS-1.3 instead of TLS-1.2 (TLS-1.2 is kept as fallback for rolling upgrades). TLS-1.2 server with {verify, verify\_peer} now defaults reuse\_sessions to false to mitigate the Triple Handshake attack (RFC 7627). Set {reuse\_sessions, true} explicitly to restore previous behavior. Various missing or faulty sanity checks added and TLS alerts adjusted to comply with RFC MUST requirements, including: signature algorithm validation for intermediate certificates, TLS-1.3 session\_id echo, pre\_shared\_key extension ordering, and renegotiation\_info enforcement. Hardened and improved CRL support. Introduces new option allowed\_hosts for the optional CRL HTTP fetching feature to restrict which hosts may be contacted. Internal/loopback IPs are now blocked by default (SSRF protection). TLS-1.3 client ticket handling is more robust (locked tickets are released on client crash). Server TLS-1.3 ticket handling and anti-replay Bloom filter performance are optimized. DTLS duplicate ChangeCipherSpec handling simplified, fixing potential state machine confusion ([GH-11075](https://github.com/erlang/otp/issues/11075)). Process state formatting no longer leaks secrets in crash logs. Own Id: OTP-20289\ Related Id(s): [PR-11478] > #### Full runtime dependencies of ssl-11.7.5 > > crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public\_key-1.21.1, runtime\_tools-1.15.1, stdlib-7.0 ### stdlib-8.0.4 The stdlib-8.0.4 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed a bug in `unicode_util:gc/1` where the grapheme cluster segmentation of `$\r` (not followed by `$\n`) would decompose binary continuations into mixed chardata. This caused `string:trim/3` (and `string:chomp/1`) to return incorrect results or crash when trimming strings containing binaries followed by another list element. Own Id: OTP-20296\ Related Id(s): [GH-11380], [PR-11464] - `record_info/2` will now mark tuple records as used. Own Id: OTP-20301\ Related Id(s): ERIERL-1345, [PR-11470] - `uri_string:parse/1` now rejects URIs with an unreasonably long port component (more than 5 digits) instead of attempting to convert an arbitrarily large digit string to an integer. Own Id: OTP-20344\ Related Id(s): [PR-11538] [CVE-2026-59696] > #### Full runtime dependencies of stdlib-8.0.4 > > compiler-5.0, crypto-4.5, erts-16.0.3, kernel-11.0, sasl-3.0, syntax\_tools-3.2.1 ### tools-4.2.2 The tools-4.2.2 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - tools: fixes tprof not stopping tracing A call to `tprof:enable_trace(new|existing)` starts tracing processes. To stop it, one calls `tprof:disable_trace(new|existing)`. However, the guard to stop tracing was matching on `new_processes | existing_processes`. The return happens to say `0` processes are traced now, but the tracing did not stop. This issue has been fixed. Own Id: OTP-20302\ Related Id(s): [PR-11481] > #### Full runtime dependencies of tools-4.2.2 > > compiler-8.5, crypto-5.9, erts-15.0, kernel-10.0, public\_key-1.21, runtime\_tools-2.1, stdlib-6.0 ### Thanks to Andrew Bennett, ausimian, Laurynas Četyrkinas, ruslandoga, Thomas Cioppettini [cve-2026-55951]: https://nvd.nist.gov/vuln/detail/CVE-2026-55951 [cve-2026-59696]: https://nvd.nist.gov/vuln/detail/CVE-2026-59696 [cve-2026-66357]: https://nvd.nist.gov/vuln/detail/CVE-2026-66357 [cve-2026-66835]: https://nvd.nist.gov/vuln/detail/CVE-2026-66835 [cve-2026-69664]: https://nvd.nist.gov/vuln/detail/CVE-2026-69664 [cve-2026-70399]: https://nvd.nist.gov/vuln/detail/cve-2026-70399 [cve-2026-70405]: https://nvd.nist.gov/vuln/detail/CVE-2026-70405 [cve-2026-70409]: https://nvd.nist.gov/vuln/detail/CVE-2026-70409 [cve-2026-71380]: https://nvd.nist.gov/vuln/detail/CVE-2026-71380 [cve-2026-71562]: https://nvd.nist.gov/vuln/detail/CVE-2026-71562 [cve-2026-73270]: https://nvd.nist.gov/vuln/detail/CVE-2026-73270 [cve-2026-73276]: https://nvd.nist.gov/vuln/detail/CVE-2026-73276 [cve-2026-73812]: https://nvd.nist.gov/vuln/detail/CVE-2026-73812 [cve-2026-74835]: https://nvd.nist.gov/vuln/detail/CVE-2026-74835 [cve-2026-74994]: https://nvd.nist.gov/vuln/detail/CVE-2026-74994 [cve-2026-75538]: https://nvd.nist.gov/vuln/detail/CVE-2026-75538 [gh-11052]: https://github.com/erlang/otp/issues/11052 [gh-11240]: https://github.com/erlang/otp/issues/11240 [gh-11278]: https://github.com/erlang/otp/issues/11278 [gh-11380]: https://github.com/erlang/otp/issues/11380 [gh-11404]: https://github.com/erlang/otp/issues/11404 [gh-11416]: https://github.com/erlang/otp/issues/11416 [gh-11419]: https://github.com/erlang/otp/issues/11419 [gh-11494]: https://github.com/erlang/otp/issues/11494 [gh-11511]: https://github.com/erlang/otp/issues/11511 [pr-11298]: https://github.com/erlang/otp/pull/11298 [pr-11325]: https://github.com/erlang/otp/pull/11325 [pr-11358]: https://github.com/erlang/otp/pull/11358 [pr-11417]: https://github.com/erlang/otp/pull/11417 [pr-11425]: https://github.com/erlang/otp/pull/11425 [pr-11428]: https://github.com/erlang/otp/pull/11428 [pr-11429]: https://github.com/erlang/otp/pull/11429 [pr-11437]: https://github.com/erlang/otp/pull/11437 [pr-11463]: https://github.com/erlang/otp/pull/11463 [pr-11464]: https://github.com/erlang/otp/pull/11464 [pr-11470]: https://github.com/erlang/otp/pull/11470 [pr-11478]: https://github.com/erlang/otp/pull/11478 [pr-11481]: https://github.com/erlang/otp/pull/11481 [pr-11485]: https://github.com/erlang/otp/pull/11485 [pr-11492]: https://github.com/erlang/otp/pull/11492 [pr-11503]: https://github.com/erlang/otp/pull/11503 [pr-11509]: https://github.com/erlang/otp/pull/11509 [pr-11513]: https://github.com/erlang/otp/pull/11513 [pr-11517]: https://github.com/erlang/otp/pull/11517 [pr-11521]: https://github.com/erlang/otp/pull/11521 [pr-11533]: https://github.com/erlang/otp/pull/11533 [pr-11538]: https://github.com/erlang/otp/pull/11538 [pr-11539]: https://github.com/erlang/otp/pull/11539 [pr-11540]: https://github.com/erlang/otp/pull/11540 [pr-11541]: https://github.com/erlang/otp/pull/11541 [pr-11542]: https://github.com/erlang/otp/pull/11542 [pr-11543]: https://github.com/erlang/otp/pull/11543 [pr-11544]: https://github.com/erlang/otp/pull/11544 [pr-11545]: https://github.com/erlang/otp/pull/11545 [pr-11546]: https://github.com/erlang/otp/pull/11546 [pr-11547]: https://github.com/erlang/otp/pull/11547 [pr-11548]: https://github.com/erlang/otp/pull/11548 [pr-11553]: https://github.com/erlang/otp/pull/11553 [pr-11554]: https://github.com/erlang/otp/pull/11554 ### [`v29.0.5`](https://github.com/erlang/otp/releases/tag/OTP-29.0.5): OTP 29.0.5 [Compare Source](https://github.com/erlang/otp/compare/OTP-29.0.4...OTP-29.0.5) ``` Patch Package: OTP 29.0.5 Git Tag: OTP-29.0.5 Date: 2026-08-04 Trouble Report Id: OTP-20137, OTP-20275 Seq num: GH-11402, PR-11110, PR-11409 System: OTP Release: 29 Application: erts-17.0.5, ssh-6.0.4 Predecessor: OTP 29.0.4 ``` Check out the git tag OTP-29.0.5, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp\_patch\_apply' tool. For information on install requirements, see descriptions for each application version below. ### erts-17.0.5 The erts-17.0.5 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed a regression in the previous patch release that prevented epmd from binding to localhost. Own Id: OTP-20275\ Related Id(s): [GH-11402], [PR-11409] > #### Full runtime dependencies of erts-17.0.5 > > kernel-9.0, sasl-3.3, stdlib-4.1 ### ssh-6.0.4 The ssh-6.0.4 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - The SSH client and server now reject incoming packets not aligned to the cipher block size as required by RFC 4253 §6. For CBC ciphers, a timing-safe "packet discard" mechanism (CVE-2008-5161 mitigation) ensures structural errors are indistinguishable from MAC failures before disconnecting. AEAD and encrypt-then-MAC modes disconnect immediately. Own Id: OTP-20137\ Related Id(s): [PR-11110] > #### Full runtime dependencies of ssh-6.0.4 > > crypto-5.7, erts-14.0, kernel-10.3, public\_key-1.6.1, runtime\_tools-1.15.1, stdlib-8.0 [gh-11402]: https://github.com/erlang/otp/issues/11402 [pr-11110]: https://github.com/erlang/otp/pull/11110 [pr-11409]: https://github.com/erlang/otp/pull/11409 ### [`v29.0.4`](https://github.com/erlang/otp/releases/tag/OTP-29.0.4): OTP 29.0.4 [Compare Source](https://github.com/erlang/otp/compare/OTP-29.0.3...OTP-29.0.4) ``` Patch Package: OTP 29.0.4 Git Tag: OTP-29.0.4 Date: 2026-07-27 Trouble Report Id: OTP-20136, OTP-20143, OTP-20214, OTP-20229, OTP-20237, OTP-20239, OTP-20240, OTP-20241, OTP-20242, OTP-20243, OTP-20244, OTP-20245, OTP-20248, OTP-20250, OTP-20251, OTP-20257, OTP-20258, OTP-20259, OTP-20260, OTP-20261 Seq num: CVE-2026-42792, CVE-2026-47078, CVE-2026-54890, CVE-2026-55737, CVE-2026-55953, CVE-2026-58227, ERIERL-1341, GH-11319, GH-11332, GH-11368, GH-SA-622p-qfh6-c352, GH-SA-7xgh-gmgf-q2g7, PR-11239, PR-11297, PR-11303, PR-11323, PR-11330, PR-11331, PR-11333, PR-11334, PR-11336, PR-11337, PR-11341, PR-11343, PR-11369, PR-11372, PR-11374, PR-11386, PR-27944 System: OTP Release: 29 Application: compiler-10.0.3, crypto-5.9.2, diameter-2.7.2, erts-17.0.4, megaco-4.9.1, public_key-1.21.4, ssh-6.0.3, ssl-11.7.4, stdlib-8.0.3 Predecessor: OTP 29.0.3 ``` Check out the git tag OTP-29.0.4, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp\_patch\_apply' tool. For information on install requirements, see descriptions for each application version below. ### POTENTIAL INCOMPATIBILITIES - Mitigated a denial of service attack in epmd. Thanks to Ryan Moore for finding and responsibly disclosing this vulnerability to the Erlang/OTP project. Own Id: OTP-20136\ Application(s): erts\ Related Id(s): [PR-11386], [CVE-2026-42792] ### compiler-10.0.3 The compiler-10.0.3 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - compiler: Fix an internal consistency check failure with `setelement` Own Id: OTP-20261\ Related Id(s): [GH-11368], [PR-11374] > #### Full runtime dependencies of compiler-10.0.3 > > crypto-5.1, erts-13.0, kernel-8.4, stdlib-8.0 ### crypto-5.9.2 The crypto-5.9.2 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed crash in `crypto:macN/5` when supplied `MacLength` was greater than length of what the underlying hash returned. Own Id: OTP-20239\ Related Id(s): [PR-11239] - Fixed segfault in `crypto:aead_cipher_init_nif` when argument validation fails. Own Id: OTP-20241\ Related Id(s): [PR-11330] - Fix cipher key buffer overread for `chacha20_poly1305`. Own Id: OTP-20244\ Related Id(s): [PR-11337] > #### Full runtime dependencies of crypto-5.9.2 > > erts-9.0, kernel-6.0, stdlib-3.9 ### diameter-2.7.2 The diameter-2.7.2 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fix infinite loop in `diameter_dist:route_session/2` when avp other than `Session-Id` has zero length. Own Id: OTP-20242\ Related Id(s): [PR-11331] - Fix crash in `diameter_dist:route_session/2` when `Session-Id` (code: 263) avp has zero length. Own Id: OTP-20243\ Related Id(s): [PR-11333] > #### Full runtime dependencies of diameter-2.7.2 > > erts-10.0, kernel-3.2, ssl-9.0, stdlib-5.0 ### erts-17.0.4 The erts-17.0.4 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Mitigated a denial of service attack in epmd. Thanks to Ryan Moore for finding and responsibly disclosing this vulnerability to the Erlang/OTP project. Own Id: OTP-20136\ Related Id(s): [PR-11386], [CVE-2026-42792] \*\*\* POTENTIAL INCOMPATIBILITY \*\*\* - Fixed heap corruption when an invalidly encoded tuple with an arity of 2^31 or larger is decoded from Erlang's External Term Format (binary\_to\_term). Own Id: OTP-20214\ Related Id(s): [PR-11297], [CVE-2026-55737] - When send\_timeout is set and send\_timeout\_close is set to true, a 'tcp\_closed' message is expected when the timeout occurs, but that (message) was not delivered. This has now been fixed. Own Id: OTP-20257\ Related Id(s): [GH-11319] - A crafted External Term Format (ETF) payload could crash the runtime system. Thanks to Paul Guyot for finding and responsibly disclosing this vulnerability to the Erlang/OTP project. Own Id: OTP-20259\ Related Id(s): [PR-11386], [CVE-2026-54890] - Fixed a rounding error in 16-bit float conversion. Own Id: OTP-20260\ Related Id(s): [GH-11332], [PR-11334] > #### Full runtime dependencies of erts-17.0.4 > > kernel-9.0, sasl-3.3, stdlib-4.1 ### megaco-4.9.1 The megaco-4.9.1 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed a buffer overflow in the megaco flex scanner C driver. A property parm name exceeding 452 bytes in a text-encoded H.248 message could overflow a fixed-size error buffer, crashing the VM. The sprintf calls have been replaced with bounded snprintf. Own Id: OTP-20237\ Related Id(s): [GH-SA-7xgh-gmgf-q2g7], [PR-11323] > #### Full runtime dependencies of megaco-4.9.1 > > asn1-3.0, debugger-4.0, erts-12.0, et-1.5, kernel-8.0, runtime\_tools-1.8.14, stdlib-2.5 ### public\_key-1.21.4 The public\_key-1.21.4 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - A certificate chain with crafted policyMappings extensions could cause exponential memory consumption during path validation, exploitable via TLS handshake. Chains exceeding a node-count cap are now rejected with {bad\_cert, policy\_tree\_exceeded}. Own Id: OTP-20251\ Related Id(s): [GH-SA-622p-qfh6-c352], [PR-11372] > #### Full runtime dependencies of public\_key-1.21.4 > > asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0 ### ssh-6.0.3 The ssh-6.0.3 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - DH key exchange now enforces strict bounds (1 < e/f < p-1, 1 < K < p-1) on all paths, matching OpenSSH and Go. No interop impact. Own Id: OTP-20229\ Related Id(s): [PR-11303] - Validate DH group parameters (P, G) received from the server during DH-GEX key exchange. The client now rejects groups where P is smaller than 2048 bits or G is not in the range (1, P-1). The default minimum in dh\_gex\_limits has been raised to 2048 on both client and server. Own Id: OTP-20258\ Related Id(s): ERIERL-1341, [PR-11369] > #### Full runtime dependencies of ssh-6.0.3 > > crypto-5.7, erts-14.0, kernel-10.3, public\_key-1.6.1, runtime\_tools-1.15.1, stdlib-8.0 ### ssl-11.7.4 Note! The ssl-11.7.4 application *cannot* be applied independently of other applications on an arbitrary OTP 29 installation. ``` On a full OTP 29 installation, also the following runtime dependency has to be satisfied: -- public_key-1.21.1 (first satisfied in OTP 29.0.1) ``` #### Fixed Bugs and Malfunctions - Add pre TLS-1.3 client side validation of servers algorithm selection being part of clients offered algorithms, preventing in worst case MITM circumventing validation of server certificate tricking the client to trust the malicious MITM as it was a valid server. Note this check is already performed for TLS-1.3 clients. Own Id: OTP-20240\ Related Id(s): [PR-11336], [CVE-2026-55953] - Prevent invalid cert chains to create cycles in chain building code used to handle chains that could be unordered or contain extraneous certs. This avoids a DoS attack possibility. Own Id: OTP-20245\ Related Id(s): [PR-11343], [CVE-2026-58227] - Clarify that rsa\_psk and anonymous key exchange algorithms are considered legacy. Also harden rsa\_psk in same way as normal rsa key exchange. Own Id: OTP-20248\ Related Id(s): [PR-11341] - Harden SSL application to conform with best practice and RFC's. This will mostly improve error messages and conserve memory usage. Own Id: OTP-20250\ Related Id(s): [PR-27944] - A certificate chain with crafted policyMappings extensions could cause exponential memory consumption during path validation, exploitable via TLS handshake. Chains exceeding a node-count cap are now rejected with {bad\_cert, policy\_tree\_exceeded}. Own Id: OTP-20251\ Related Id(s): [GH-SA-622p-qfh6-c352], [PR-11372] > #### Full runtime dependencies of ssl-11.7.4 > > crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public\_key-1.21.1, runtime\_tools-1.15.1, stdlib-7.0 ### stdlib-8.0.3 The stdlib-8.0.3 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed a bug where zip:unzip/1,2 and zip:extract/1,2 were vulnerable to a relative path traversal attack. A crafted zip archive containing entry names such as ../x/y could have caused files to be written outside the intended extraction directory. Thanks to Jonatan Männchen and Zhang Delong for finding and responsibly disclosing this vulnerability to the Erlang/OTP project. Own Id: OTP-20143\ Related Id(s): [PR-11386], [CVE-2026-47078] > #### Full runtime dependencies of stdlib-8.0.3 > > compiler-5.0, crypto-4.5, erts-16.0.3, kernel-11.0, sasl-3.0, syntax\_tools-3.2.1 ### Thanks to a1x-an, Jonatan Männchen [cve-2026-42792]: https://nvd.nist.gov/vuln/detail/CVE-2026-42792 [cve-2026-47078]: https://nvd.nist.gov/vuln/detail/CVE-2026-47078 [cve-2026-54890]: https://nvd.nist.gov/vuln/detail/CVE-2026-54890 [cve-2026-55737]: https://nvd.nist.gov/vuln/detail/CVE-2026-55737 [cve-2026-55953]: https://nvd.nist.gov/vuln/detail/CVE-2026-55953 [cve-2026-58227]: https://nvd.nist.gov/vuln/detail/CVE-2026-58227 [gh-11319]: https://github.com/erlang/otp/issues/11319 [gh-11332]: https://github.com/erlang/otp/issues/11332 [gh-11368]: https://github.com/erlang/otp/issues/11368 [gh-sa-622p-qfh6-c352]: https://github.com/erlang/otp/issues/SA-622p-qfh6-c352 [gh-sa-7xgh-gmgf-q2g7]: https://github.com/erlang/otp/issues/SA-7xgh-gmgf-q2g7 [pr-11239]: https://github.com/erlang/otp/pull/11239 [pr-11297]: https://github.com/erlang/otp/pull/11297 [pr-11303]: https://github.com/erlang/otp/pull/11303 [pr-11323]: https://github.com/erlang/otp/pull/11323 [pr-11330]: https://github.com/erlang/otp/pull/11330 [pr-11331]: https://github.com/erlang/otp/pull/11331 [pr-11333]: https://github.com/erlang/otp/pull/11333 [pr-11334]: https://github.com/erlang/otp/pull/11334 [pr-11336]: https://github.com/erlang/otp/pull/11336 [pr-11337]: https://github.com/erlang/otp/pull/11337 [pr-11341]: https://github.com/erlang/otp/pull/11341 [pr-11343]: https://github.com/erlang/otp/pull/11343 [pr-11369]: https://github.com/erlang/otp/pull/11369 [pr-11372]: https://github.com/erlang/otp/pull/11372 [pr-11374]: https://github.com/erlang/otp/pull/11374 [pr-11386]: https://github.com/erlang/otp/pull/11386 [pr-27944]: https://github.com/erlang/otp/pull/27944 ### [`v29.0.3`](https://github.com/erlang/otp/releases/tag/OTP-29.0.3): OTP 29.0.3 [Compare Source](https://github.com/erlang/otp/compare/OTP-29.0.2...OTP-29.0.3) ``` Patch Package: OTP 29.0.3 Git Tag: OTP-29.0.3 Date: 2026-07-02 Trouble Report Id: OTP-20173, OTP-20183, OTP-20185, OTP-20186, OTP-20190, OTP-20191, OTP-20194, OTP-20196, OTP-20197, OTP-20198, OTP-20199, OTP-20200, OTP-20201, OTP-20206, OTP-20207, OTP-20208, OTP-20215, OTP-20216, OTP-20217, OTP-20220, OTP-20222, OTP-20226, OTP-20227, OTP-20230, OTP-20231, OTP-20232, OTP-20233 Seq num: CVE-2026-53422, CVE-2026-54886, CVE-2026-54887, CVE-2026-54891, CVE-2026-55950, CVE-2026-55952, ERIERL-1333, GH-SA-7wp4-pc27-2vj9, GH-SA-h9pw-h5w4-h976, PR-11209, PR-11215, PR-11219, PR-11230, PR-11239, PR-11244, PR-11247, PR-11250, PR-11259, PR-11268, PR-11269, PR-11270, PR-11271, PR-11281, PR-11282, PR-11283, PR-11289, PR-11294, PR-11295, PR-11299, PR-11302, PR-11306, PR-11307, PR-11309, PR-11311 System: OTP Release: 29 Application: common_test-1.31.1, compiler-10.0.2, crypto-5.9.1, dialyzer-6.0.2, erts-17.0.3, kernel-11.0.3, public_key-1.21.3, ssh-6.0.2, ssl-11.7.3, stdlib-8.0.2 Predecessor: OTP 29.0.2 ``` Check out the git tag OTP-29.0.3, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp\_patch\_apply' tool. For information on install requirements, see descriptions for each application version below. ### common\_test-1.31.1 The common\_test-1.31.1 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed a crash in ct\_netconfc that occurred when the remote server closed the SSH connection during NETCONF subsystem negotiation. Own Id: OTP-20191\ Related Id(s): ERIERL-1333, [PR-11230] > #### Full runtime dependencies of common\_test-1.31.1 > > compiler-10.0, crypto-4.5, debugger-4.1, erts-7.0, ftp-1.0, inets-6.0, kernel-11.0, observer-2.1, runtime\_tools-1.8.16, sasl-2.5, snmp-5.1.2, ssh-4.0, stdlib-8.0, syntax\_tools-1.7, tools-3.2, xmerl-1.3.8 ### compiler-10.0.2 The compiler-10.0.2 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Several compiler bugs that could crash the compiler or generate incorrect code in rare circumstances have been fixed. Own Id: OTP-20222\ Related Id(s): [PR-11219] > #### Full runtime dependencies of compiler-10.0.2 > > crypto-5.1, erts-13.0, kernel-8.4, stdlib-8.0 ### crypto-5.9.1 The crypto-5.9.1 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - `crypto:compute_key/4` for `eddh` and `crypto:generate_key/2,3` for `eddh`/`eddsa` now raise an `error:{notsup, Info, Description}` exception instead of returning the atom `notsup` when the underlying cryptolib lacks support. Own Id: OTP-20215\ Related Id(s): [PR-11302] > #### Full runtime dependencies of crypto-5.9.1 > > erts-9.0, kernel-6.0, stdlib-3.9 ### dialyzer-6.0.2 The dialyzer-6.0.2 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fix a bug with native record sets in `erl_types.erl` Own Id: OTP-20201 > #### Full runtime dependencies of dialyzer-6.0.2 > > compiler-10.0, erts-12.0, kernel-8.0, stdlib-5.0, syntax\_tools-2.0 ### erts-17.0.3 The erts-17.0.3 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed an undefined behavior in the internal `erts_qsort()` function, which could have been the cause of a beam crash seen when updating large maps. Own Id: OTP-20185\ Related Id(s): [PR-11215] - Calculating `bxor` of the largest supported positive integer (`erlang:system_info(max_integer)`) and `-1` would return `[]` instead of a raising a `system_limit` exception. Own Id: OTP-20208\ Related Id(s): [PR-11269] - Fix possible race between `ets:delete/1` and terminating process with a fixation on the same table. Own Id: OTP-20217\ Related Id(s): [PR-11283] - A few code generation issues for the JIT on AArch64 (ARM64) have been fixed. For all platforms, the loader will reject some invalid BEAM files earlier. Own Id: OTP-20226\ Related Id(s): [PR-11299] - On 32-bit computers, the `md5` BIFs would return an incorrect MD5 checksum for data of size 4GiB or more. Own Id: OTP-20227\ Related Id(s): [PR-11289] > #### Full runtime dependencies of erts-17.0.3 > > kernel-9.0, sasl-3.3, stdlib-4.1 ### kernel-11.0.3 The kernel-11.0.3 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - inet:info/1 could crash when calling for a closing (port) socket. Own Id: OTP-20173 - Handling of the truncation bit in `inet_res` has been fixed so it properly falls back to querying over TCP after a truncated UDP reply. This fixes a bug introduced in OTP-28.4.2 - kernel-10.6.2 making a truncated UDP answer fail to parse and never execute the fallback, instead the name resolve operation fails. Own Id: OTP-20199\ Related Id(s): [PR-11247] > #### Full runtime dependencies of kernel-11.0.3 > > crypto-5.8, erts-17.0, sasl-3.0, stdlib-8.0 ### public\_key-1.21.3 The public\_key-1.21.3 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Hardened OCSP response verification by using constant-time hash comparisons and rejecting responses exceeding 100 KB before ASN.1 decoding. Own Id: OTP-20197\ Related Id(s): [PR-11239] > #### Full runtime dependencies of public\_key-1.21.3 > > asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0 ### ssh-6.0.2 The ssh-6.0.2 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed a path-existence oracle in the SFTP server where `SSH_FXP_REALPATH` requests with `..` components could bypass the configured root directory isolation, allowing an authenticated client to determine whether arbitrary paths exist on the host filesystem. Own Id: OTP-20183\ Related Id(s): [GH-SA-h9pw-h5w4-h976], [PR-11294], [CVE-2026-53422] - Fixed an infinite loop in the SFTP server triggered when receiving `SSH_MSG_CHANNEL_EXTENDED_DATA` on an SFTP channel, which caused the channel process to spin indefinitely on CPU without consuming its message queue. Own Id: OTP-20186\ Related Id(s): [GH-SA-7wp4-pc27-2vj9], [PR-11295], [CVE-2026-54886] - Fixed mlkem768x25519 hybrid key exchange failing intermittently with "incorrect signature" when the X25519 shared secret had a leading zero byte. The shared secret is now encoded as a fixed-width 32-byte string per the specification. Own Id: OTP-20196\ Related Id(s): [PR-11209] - Fixed a race condition where SSH keepalive responses could be matched to unrelated pending requests due to incorrect request queue ordering. Requests are now matched in the order they were sent. Own Id: OTP-20198\ Related Id(s): [PR-11244] - The SFTP server now caps the read length in `SSH_FXP_READ` requests to 255 KiB (matching OpenSSH's `SFTP_MAX_READ_LENGTH`), preventing excessive memory allocation when clients request large reads. Own Id: OTP-20200\ Related Id(s): [PR-11259] - Removed a server-side workaround (OTP-14827, introduced in OTP 20) that accepted SHA-1 user-auth signatures from clients identifying as OpenSSH 7.x when rsa-sha2-\* was negotiated. The workaround addressed a distro-specific build issue in 2017 that no longer exists. Clients affected by this removal (extremely unlikely — requires a 10-year-old unpatched OpenSSH build) will see authentication failures and must upgrade. Own Id: OTP-20206\ Related Id(s): [PR-11268] > #### Full runtime dependencies of ssh-6.0.2 > > crypto-5.7, erts-14.0, kernel-10.3, public\_key-1.6.1, runtime\_tools-1.15.1, stdlib-8.0 ### ssl-11.7.3 Note! The ssl-11.7.3 application *cannot* be applied independently of other applications on an arbitrary OTP 29 installation. ``` On a full OTP 29 installation, also the following runtime dependency has to be satisfied: -- public_key-1.21.1 (first satisfied in OTP 29.0.1) ``` #### Fixed Bugs and Malfunctions - Correct small behavior bugs that occasionally could cause DTLS connection errors, unwanted behavior for legacy DHE\_DSS, hiding of a distribution config error, and possible unorderly process tree shutdown. Own Id: OTP-20190\ Related Id(s): [PR-11250] - Initialize DTLS cookie to random value to avoid DoS attack with forged cookie during startup window. Own Id: OTP-20194\ Related Id(s): [PR-11271], [CVE-2026-54887] - Guard TLS client for MITM injection of application data during "plain-text-window" during handshake. Own Id: OTP-20207\ Related Id(s): [PR-11270], [CVE-2026-54891] - Improve error handling of TLS PSK sending ILLIGAL\_PARMETER alert if binders and PSK-identities are not matched. Also mend recovery mechanism of ticket and session stores to be as resilient as possible to intermediate bugs. Own Id: OTP-20216\ Related Id(s): [PR-11282], [CVE-2026-55952] - Fix race condition that could be used to DoS attack DTLS servers. Own Id: OTP-20220\ Related Id(s): [PR-11306], [CVE-2026-55950] - A TLS-1.3 stateless session ticket with obfuscated\_ticket\_age set to zero was incorrectly accepted without checking the server-side ticket lifetime or the RFC 8446 Section 8.3 freshness window. The server now always validates ticket age using its own timestamp regardless of the client-reported age value. Own Id: OTP-20230\ Related Id(s): [PR-11307] - TLS-1.3 client rejects a second HelloRetryRequest as requiered in RFC 8446 Section 4.1.4 Own Id: OTP-20231\ Related Id(s): [PR-11309] - A busy client node could self-trigger a ticket store crash if unlucky with scheduling if auto mode is used. Own Id: OTP-20232\ Related Id(s): [PR-11311] - Correct spec for CRL API Own Id: OTP-20233\ Related Id(s): [PR-11281] > #### Full runtime dependencies of ssl-11.7.3 > > crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public\_key-1.21.1, runtime\_tools-1.15.1, stdlib-7.0 ### stdlib-8.0.2 The stdlib-8.0.2 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Several compiler bugs that could crash the compiler or generate incorrect code in rare circumstances have been fixed. Own Id: OTP-20222\ Related Id(s): [PR-11219] > #### Full runtime dependencies of stdlib-8.0.2 > > compiler-5.0, crypto-4.5, erts-16.0.3, kernel-11.0, sasl-3.0, syntax\_tools-3.2.1 ### Thanks to Cole Christensen, Nick Krichevsky, Stefan Grundmann [cve-2026-53422]: https://nvd.nist.gov/vuln/detail/CVE-2026-53422 [cve-2026-54886]: https://nvd.nist.gov/vuln/detail/CVE-2026-54886 [cve-2026-54887]: https://nvd.nist.gov/vuln/detail/CVE-2026-54887 [cve-2026-54891]: https://nvd.nist.gov/vuln/detail/CVE-2026-54891 [cve-2026-55950]: https://nvd.nist.gov/vuln/detail/CVE-2026-55950 [cve-2026-55952]: https://nvd.nist.gov/vuln/detail/CVE-2026-55952 [gh-sa-7wp4-pc27-2vj9]: https://github.com/erlang/otp/issues/SA-7wp4-pc27-2vj9 [gh-sa-h9pw-h5w4-h976]: https://github.com/erlang/otp/issues/SA-h9pw-h5w4-h976 [pr-11209]: https://github.com/erlang/otp/pull/11209 [pr-11215]: https://github.com/erlang/otp/pull/11215 [pr-11219]: https://github.com/erlang/otp/pull/11219 [pr-11230]: https://github.com/erlang/otp/pull/11230 [pr-11239]: https://github.com/erlang/otp/pull/11239 [pr-11244]: https://github.com/erlang/otp/pull/11244 [pr-11247]: https://github.com/erlang/otp/pull/11247 [pr-11250]: https://github.com/erlang/otp/pull/11250 [pr-11259]: https://github.com/erlang/otp/pull/11259 [pr-11268]: https://github.com/erlang/otp/pull/11268 [pr-11269]: https://github.com/erlang/otp/pull/11269 [pr-11270]: https://github.com/erlang/otp/pull/11270 [pr-11271]: https://github.com/erlang/otp/pull/11271 [pr-11281]: https://github.com/erlang/otp/pull/11281 [pr-11282]: https://github.com/erlang/otp/pull/11282 [pr-11283]: https://github.com/erlang/otp/pull/11283 [pr-11289]: https://github.com/erlang/otp/pull/11289 [pr-11294]: https://github.com/erlang/otp/pull/11294 [pr-11295]: https://github.com/erlang/otp/pull/11295 [pr-11299]: https://github.com/erlang/otp/pull/11299 [pr-11302]: https://github.com/erlang/otp/pull/11302 [pr-11306]: https://github.com/erlang/otp/pull/11306 [pr-11307]: https://github.com/erlang/otp/pull/11307 [pr-11309]: https://github.com/erlang/otp/pull/11309 [pr-11311]: https://github.com/erlang/otp/pull/11311 ### [`v29.0.2`](https://github.com/erlang/otp/releases/tag/OTP-29.0.2): OTP 29.0.2 [Compare Source](https://github.com/erlang/otp/compare/OTP-29.0.1...OTP-29.0.2) ``` Patch Package: OTP 29.0.2 Git Tag: OTP-29.0.2 Date: 2026-06-10 Trouble Report Id: OTP-20057, OTP-20149, OTP-20150, OTP-20151, OTP-20153, OTP-20154, OTP-20155, OTP-20156, OTP-20160, OTP-20161, OTP-20162, OTP-20163, OTP-20165, OTP-20166, OTP-20170, OTP-20172, OTP-20174, OTP-20178, OTP-20181 Seq num: CVE-2026-48855, CVE-2026-48856, CVE-2026-48858, CVE-2026-48859, CVE-2026-48860, CVE-2026-49759, CVE-2026-49760, GH-11104, GH-11105, GH-11152, GH-SA-24cv-hwgr-37fq, GH-SA-3w6p-vwhf-wvp4, GH-SA-6f4f-chj5-5g97, GH-SA-gp7x-mfv6-52cv, GH-SA-m75x-4vwg-ggjh, GH-SA-pv7g-pjrq-x2fh, GH-SA-xcxj-5pg2-v72j, PR-11141, PR-11145, PR-11146, PR-11148, PR-11154, PR-11157, PR-11168, PR-11181, PR-11186, PR-11192, PR-11193, PR-11195, PR-11199, PR-11205, PR-11212, PR-1234, PR-27384 System: OTP Release: 29 Application: dialyzer-6.0.1, diameter-2.7.1, erl_interface-5.8.1, erts-17.0.2, ftp-1.2.6, inets-9.7.1, kernel-11.0.2, mnesia-4.26.1, public_key-1.21.2, ssh-6.0.1, ssl-11.7.2, stdlib-8.0.1, tools-4.2.1 Predecessor: OTP 29.0.1 ``` Check out the git tag OTP-29.0.2, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp\_patch\_apply' tool. For information on install requirements, see descriptions for each application version below. ### dialyzer-6.0.1 The dialyzer-6.0.1 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fix native record bugs in Dialyzer Own Id: OTP-20178\ Related Id(s): [PR-11199] > #### Full runtime dependencies of dialyzer-6.0.1 > > compiler-10.0, erts-12.0, kernel-8.0, stdlib-5.0, syntax\_tools-2.0 ### diameter-2.7.1 The diameter-2.7.1 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed return value documentation of `diameter:service_info(SvcName, statistics)` Own Id: OTP-20150\ Related Id(s): [GH-11105], [PR-11146] > #### Full runtime dependencies of diameter-2.7.1 > > erts-10.0, kernel-3.2, ssl-9.0, stdlib-5.0 ### erl\_interface-5.8.1 The erl\_interface-5.8.1 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed stack overflow in `ei_s_print_term` for very big integer terms (> 2000 hexadecimal digits long). Own Id: OTP-20160\ Related Id(s): [GH-SA-xcxj-5pg2-v72j], [PR-11193], [CVE-2026-49760] ### erts-17.0.2 The erts-17.0.2 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - A buffer overflow error when parsing SCTP ERROR or ABORT chunks has been fixed. This could lead to stack corruption and VM crash, but ultimately with hard work by an attacker be refined into maybe even remote code execution. Own Id: OTP-20165\ Related Id(s): [GH-SA-6f4f-chj5-5g97], [PR-1234], [CVE-2026-49759] > #### Full runtime dependencies of erts-17.0.2 > > kernel-9.0, sasl-3.3, stdlib-4.1 ### ftp-1.2.6 The ftp-1.2.6 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - FTP client default connections that use the so called passive mode of FTP fails to properly validating the response IP of the server, hence a malicious or compromised FTP server could redirect the data connection to an arbitrary host, enabling s server-side request forgery (SSRF) and FTP bounce attacks. Own Id: OTP-20166\ Related Id(s): [GH-SA-24cv-hwgr-37fq], [PR-11186], [CVE-2026-48858] > #### Full runtime dependencies of ftp-1.2.6 > > erts-7.0, kernel-6.0, runtime\_tools-1.15.1, ssl-10.2, stdlib-3.5 ### inets-9.7.1 The inets-9.7.1 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - The HTTP client (httpc) now removes Authorization, Proxy-Authorization, Cookie, Referer, and Origin headers when following a redirect to a different host or port. Previously these headers were forwarded verbatim, potentially leaking credentials to unintended targets. This follows the requirements of RFC 9110 §15.4. Own Id: OTP-20155\ Related Id(s): [GH-SA-m75x-4vwg-ggjh], [PR-11212], [CVE-2026-48856] > #### Full runtime dependencies of inets-9.7.1 > > erts-14.0, kernel-9.0, mnesia-4.12, public\_key-1.13, runtime\_tools-1.8.14, ssl-9.0, stdlib-5.0, stdlib-6.0 ### kernel-11.0.2 The kernel-11.0.2 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - gen\_tcp\_socket accept should explicitly inherit the same options as plain gen\_tcp. Own Id: OTP-20057 > #### Full runtime dependencies of kernel-11.0.2 > > crypto-5.8, erts-17.0, sasl-3.0, stdlib-8.0 ### mnesia-4.26.1 The mnesia-4.26.1 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed docs of `mnesia:write/3` to clarify when a transaction can terminate. Own Id: OTP-20149\ Related Id(s): [GH-11104], [PR-11145] > #### Full runtime dependencies of mnesia-4.26.1 > > erts-9.0, kernel-5.3, stdlib-5.0 ### public\_key-1.21.2 The public\_key-1.21.2 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Add missing macro reference for legacy algorithms md5 and sha224. This mainly improves error handling. Own Id: OTP-20172\ Related Id(s): [PR-11195] > #### Full runtime dependencies of public\_key-1.21.2 > > asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0 ### ssh-6.0.1 The ssh-6.0.1 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fixed a timing-based username enumeration vulnerability during password authentication with the user\_passwords option. A dummy PBKDF2 computation is now performed for invalid usernames to match the response time of valid ones. Own Id: OTP-20153\ Related Id(s): [GH-SA-3w6p-vwhf-wvp4], [PR-11157], [CVE-2026-48859] - Fixed SSH\_FXP\_READLINK handler in ssh\_sftpd to strip the backend root prefix from symlink targets before returning them to the client, preventing disclosure of the server's absolute filesystem path when the root option is configured. Own Id: OTP-20162\ Related Id(s): [GH-SA-pv7g-pjrq-x2fh], [PR-11192], [CVE-2026-48855] - Fixed a race condition where SSH keep-alive responses could consume pending channel open requests, causing channel setup to fail silently. Own Id: OTP-20181\ Related Id(s): [PR-11205] > #### Full runtime dependencies of ssh-6.0.1 > > crypto-5.7, erts-14.0, kernel-10.3, public\_key-1.6.1, runtime\_tools-1.15.1, stdlib-8.0 ### ssl-11.7.2 Note! The ssl-11.7.2 application *cannot* be applied independently of other applications on an arbitrary OTP 29 installation. ``` On a full OTP 29 installation, also the following runtime dependency has to be satisfied: -- public_key-1.21.1 (first satisfied in OTP 29.0.1) ``` #### Fixed Bugs and Malfunctions - Fix miscellanies issues that could cause unnecessary memory consumption and in some less common scenarios or configurations cause connection failures. Own Id: OTP-20154\ Related Id(s): [PR-11148] - Erlang distribution over TLS run with the kernel 'check\_ip' flag now properly enforce connecting nodes to be on the same LAN. Own Id: OTP-20156\ Related Id(s): [GH-SA-gp7x-mfv6-52cv], [PR-11181], [CVE-2026-48860] - Enhance error message, by fixing typo of atom in new error message related to \`public\_key\` CVE-2026-42790 solution. Own Id: OTP-20161\ Related Id(s): [PR-11148] - Corrected SNI handling for TLS-1.3 only server, could cause connection failures if supported signature algorithms where changed by SNI option update. Own Id: OTP-20174\ Related Id(s): [PR-27384] > #### Full runtime dependencies of ssl-11.7.2 > > crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public\_key-1.21.1, runtime\_tools-1.15.1, stdlib-7.0 ### stdlib-8.0.1 The stdlib-8.0.1 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Fix a bug where a tuple record operation within a native record anonymous update can crash. Own Id: OTP-20151\ Related Id(s): [PR-11141] - Fixed some bugs in `io_lib:bformat/2` and native record printing. Own Id: OTP-20170\ Related Id(s): [PR-11154] > #### Full runtime dependencies of stdlib-8.0.1 > > compiler-5.0, crypto-4.5, erts-16.0.3, kernel-11.0, sasl-3.0, syntax\_tools-3.2.1 ### tools-4.2.1 The tools-4.2.1 application can be applied independently of other applications on a full OTP 29 installation. #### Fixed Bugs and Malfunctions - Xref could crash instead of returning an appropriate error tuple when asked to open a BEAM file without debug information but with a `moduledoc(false)` attribute. Own Id: OTP-20163\ Related Id(s): [GH-11152], [PR-11168] > #### Full runtime dependencies of tools-4.2.1 > > compiler-8.5, crypto-5.9, erts-15.0, kernel-10.0, public\_key-1.21, runtime\_tools-2.1, stdlib-6.0 ### Thanks to John Downey, Jonatan Männchen [cve-2026-48855]: https://nvd.nist.gov/vuln/detail/CVE-2026-48855 [cve-2026-48856]: https://nvd.nist.gov/vuln/detail/CVE-2026-48856 [cve-2026-48858]: https://nvd.nist.gov/vuln/detail/CVE-2026-48858 [cve-2026-48859]: https://nvd.nist.gov/vuln/detail/CVE-2026-48859 [cve-2026-48860]: https://nvd.nist.gov/vuln/detail/CVE-2026-48860 [cve-2026-49759]: https://nvd.nist.gov/vuln/detail/CVE-2026-49759 [cve-2026-49760]: https://nvd.nist.gov/vuln/detail/CVE-2026-49760 [gh-11104]: https://github.com/erlang/otp/issues/11104 [gh-11105]: https://github.com/erlang/otp/issues/11105 [gh-11152]: https://github.com/erlang/otp/issues/11152 [gh-sa-24cv-hwgr-37fq]: https://github.com/erlang/otp/issues/SA-24cv-hwgr-37fq [gh-sa-3w6p-vwhf-wvp4]: https://github.com/erlang/otp/issues/SA-3w6p-vwhf-wvp4 [gh-sa-6f4f-chj5-5g97]: https://github.com/erlang/otp/issues/SA-6f4f-chj5-5g97 [gh-sa-gp7x-mfv6-52cv]: https://github.com/erlang/otp/issues/SA-gp7x-mfv6-52cv [gh-sa-m75x-4vwg-ggjh]: https://github.com/erlang/otp/issues/SA-m75x-4vwg-ggjh [gh-sa-pv7g-pjrq-x2fh]: https://github.com/erlang/otp/issues/SA-pv7g-pjrq-x2fh [gh-sa-xcxj-5pg2-v72j]: https://github.com/erlang/otp/issues/SA-xcxj-5pg2-v72j [pr-11141]: https://github.com/erlang/otp/pull/11141 [pr-11145]: https://github.com/erlang/otp/pull/11145 [pr-11146]: https://github.com/erlang/otp/pull/11146 [pr-11148]: https://github.com/erlang/otp/pull/11148 [pr-11154]: https://github.com/erlang/otp/pull/11154 [pr-11157]: https://github.com/erlang/otp/pull/11157 [pr-11168]: https://github.com/erlang/otp/pull/11168 [pr-11181]: https://github.com/erlang/otp/pull/11181 [pr-11186]: https://github.com/erlang/otp/pull/11186 [pr-11192]: https://github.com/erlang/otp/pull/11192 [pr-11193]: https://github.com/erlang/otp/pull/11193 [pr-11195]: https://github.com/erlang/otp/pull/11195 [pr-11199]: https://github.com/erlang/otp/pull/11199 [pr-11205]: https://github.com/erlang/otp/pull/11205 [pr-11212]: https://github.com/erlang/otp/pull/11212 [pr-1234]: https://github.com/erlang/otp/pull/1234 [pr-27384]: https://github.com/erlang/otp/pull/27384 </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNTAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjE1MC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
renovate changed title from Update dependency erlang to v29.0.6 to chore(deps): update dependency erlang to v29.0.6 2026-09-05 15:00:39 +02:00
renovate changed title from chore(deps): update dependency erlang to v29.0.6 to Update dependency erlang to v29.0.6 2026-09-07 12:00:25 +02:00
renovate changed title from Update dependency erlang to v29.0.6 to chore(deps): update dependency erlang to v29.0.6 2026-09-12 00:00:29 +02:00
renovate changed title from chore(deps): update dependency erlang to v29.0.6 to chore(deps): update dependency erlang to v29.1 2026-09-16 15:00:52 +02:00
renovate force-pushed renovate/erlang-29.x from 653c1143a0 to f3a713601d 2026-09-16 15:00:52 +02:00 Compare
renovate force-pushed renovate/erlang-29.x from f3a713601d to 3cfce07776 2026-09-17 12:00:54 +02:00 Compare
renovate force-pushed renovate/erlang-29.x from 3cfce07776 to d65ab92e42 2026-09-22 12:00:39 +02:00 Compare
renovate changed title from chore(deps): update dependency erlang to v29.1 to chore(deps): update dependency erlang to v29.1.1 2026-09-22 12:00:40 +02:00
This pull request can be merged automatically.
This branch is out-of-date with the base branch
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/erlang-29.x:renovate/erlang-29.x
git switch renovate/erlang-29.x
Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
inhji/hajur!233
No description provided.