aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorLoïc Hoguin <[email protected]>2025-06-19 14:14:22 +0200
committerLoïc Hoguin <[email protected]>2025-06-19 14:14:22 +0200
commita26a4b5b3785f788693895ee3f9cfec56da9a35c (patch)
tree8619df31b7c9b7a8df2e03a43c46c20bdf776f67
parent0bde14f3dabf102cbbb473974ac588af73fc9ecd (diff)
downloadci.erlang.mk-a26a4b5b3785f788693895ee3f9cfec56da9a35c.tar.gz
ci.erlang.mk-a26a4b5b3785f788693895ee3f9cfec56da9a35c.tar.bz2
ci.erlang.mk-a26a4b5b3785f788693895ee3f9cfec56da9a35c.zip
OTP-26.2.5.13
-rw-r--r--early-plugins.mk4
-rw-r--r--release-notes/OTP-26.2.5.13.README.txt143
2 files changed, 145 insertions, 2 deletions
diff --git a/early-plugins.mk b/early-plugins.mk
index 495e4fb..44569c9 100644
--- a/early-plugins.mk
+++ b/early-plugins.mk
@@ -20,7 +20,7 @@ OTP-22 := OTP-22.0.7 OTP-22.1.8 OTP-22.2.8 OTP-22.3.4.27
OTP-23 := OTP-23.0.4 OTP-23.1.5 OTP-23.2.7.3 OTP-23.3.4.20
OTP-24 := OTP-24.0.6 OTP-24.1.7 OTP-24.2.2 OTP-24.3.4.17
OTP-25 := OTP-25.0.4 OTP-25.1.2.1 OTP-25.2.3 OTP-25.3.2.21
-OTP-26 := OTP-26.0.2 OTP-26.1.2 OTP-26.2.5.12
+OTP-26 := OTP-26.0.2 OTP-26.1.2 OTP-26.2.5.13
OTP-27 := OTP-27.0.1 OTP-27.1.3 OTP-27.2.4 OTP-27.3.4.1
OTP-28 := OTP-28.0
@@ -125,7 +125,7 @@ OTP-25-DROPPED := OTP-25.0-rc1 OTP-25.0-rc2 OTP-25.0-rc3 OTP-25.0 \
OTP-25.2.1 OTP-25.2.2 OTP-25.3 OTP-25.3.1 OTP-25.3.2 OTP-25.3.2.1 OTP-25.3.2.2 \
OTP-25.3.2.3 OTP-25.3.2.4 OTP-25.3.2.5 OTP-25.3.2.6 OTP-25.3.2.7 OTP-25.3.2.8 OTP-25.3.2.9 OTP-25.3.2.10 OTP-25.3.2.11 OTP-25.3.2.12 OTP-25.3.2.13 OTP-25.3.2.14 OTP-25.3.2.15 OTP-25.3.2.16 OTP-25.3.2.17 OTP-25.3.2.18 OTP-25.3.2.19 OTP-25.3.2.20
OTP-26-DROPPED := OTP-26.0-rc3 \
- OTP-26.0 OTP-26.0.1 OTP-26.1 OTP-26.1.1 OTP-26.2 OTP-26.2.1 OTP-26.2.2 OTP-26.2.3 OTP-26.2.4 OTP-26.2.5 OTP-26.2.5.1 OTP-26.2.5.2 OTP-26.2.5.3 OTP-26.2.5.4 OTP-26.2.5.5 OTP-26.2.5.6 OTP-26.2.5.7 OTP-26.2.5.8 OTP-26.2.5.9 OTP-26.2.5.10 OTP-26.2.5.11
+ OTP-26.0 OTP-26.0.1 OTP-26.1 OTP-26.1.1 OTP-26.2 OTP-26.2.1 OTP-26.2.2 OTP-26.2.3 OTP-26.2.4 OTP-26.2.5 OTP-26.2.5.1 OTP-26.2.5.2 OTP-26.2.5.3 OTP-26.2.5.4 OTP-26.2.5.5 OTP-26.2.5.6 OTP-26.2.5.7 OTP-26.2.5.8 OTP-26.2.5.9 OTP-26.2.5.10 OTP-26.2.5.11 OTP-26.2.5.12
OTP-27-DROPPED := OTP-27.0-rc1 OTP-27.0-rc2 \
OTP-27.1.2 OTP-27.2 OTP-27.2.1 OTP-27.2.2 OTP-27.2.3 OTP-27.3 OTP-27.3.1 OTP-27.3.2 OTP-27.3.3 OTP-27.3.4
OTP-28-DROPPED := OTP-28.0-rc1 OTP-28.0-rc2 OTP-28.0-rc3 OTP-28.0-rc4
diff --git a/release-notes/OTP-26.2.5.13.README.txt b/release-notes/OTP-26.2.5.13.README.txt
new file mode 100644
index 0000000..a3ed17b
--- /dev/null
+++ b/release-notes/OTP-26.2.5.13.README.txt
@@ -0,0 +1,143 @@
+Patch Package: OTP 26.2.5.13
+Git Tag: OTP-26.2.5.13
+Date: 2025-06-16
+Trouble Report Id: OTP-19634, OTP-19637, OTP-19638, OTP-19649,
+ OTP-19653, OTP-19667
+Seq num: CVE-2025-4748, GH-6463, GH-9102, GH-9771,
+ GH-9841, PR-9103, PR-9838, PR-9846, PR-9898,
+ PR-9912, PR-9941
+System: OTP
+Release: 26
+Application: asn1-5.2.2.1, kernel-9.2.4.9, ssh-5.1.4.10,
+ stdlib-5.2.3.4
+Predecessor: OTP 26.2.5.12
+
+ Check out the git tag OTP-26.2.5.13, and build a full OTP system
+ including documentation. Apply one or more applications from this
+ build as patches to your installation using the 'otp_patch_apply'
+ tool. For information on install requirements, see descriptions for
+ each application version below.
+
+ ---------------------------------------------------------------------
+ --- asn1-5.2.2.1 ----------------------------------------------------
+ ---------------------------------------------------------------------
+
+ The asn1-5.2.2.1 application can be applied independently of other
+ applications on a full OTP 26 installation.
+
+ --- Fixed Bugs and Malfunctions ---
+
+ OTP-19638 Application(s): asn1
+ Related Id(s): GH-9841, PR-9846
+
+ The ASN.1 compiler could generate code that would cause
+ Dialyzer with the unmatched_returns option to emit
+ warnings.
+
+
+ Full runtime dependencies of asn1-5.2.2.1: erts-11.0, kernel-7.0,
+ stdlib-3.13
+
+
+ ---------------------------------------------------------------------
+ --- kernel-9.2.4.9 --------------------------------------------------
+ ---------------------------------------------------------------------
+
+ The kernel-9.2.4.9 application can be applied independently of other
+ applications on a full OTP 26 installation.
+
+ --- Fixed Bugs and Malfunctions ---
+
+ OTP-19667 Application(s): kernel, stdlib
+ Related Id(s): PR-9912
+
+ A remote shell can now exit by closing the input
+ stream, without terminating the remote node.
+
+
+ Full runtime dependencies of kernel-9.2.4.9: crypto-5.0, erts-14.0,
+ sasl-3.0, stdlib-5.0
+
+
+ ---------------------------------------------------------------------
+ --- ssh-5.1.4.10 ----------------------------------------------------
+ ---------------------------------------------------------------------
+
+ The ssh-5.1.4.10 application can be applied independently of other
+ applications on a full OTP 26 installation.
+
+ --- Fixed Bugs and Malfunctions ---
+
+ OTP-19634 Application(s): ssh
+ Related Id(s): GH-9102, PR-9103
+
+ Various channel closing robustness improvements. Avoid
+ crashes when channel handling process closes channel
+ and immediately exits. Avoid breaking the protocol by
+ sending duplicated channel-close messages. Cleanup
+ channels which timeout during closing procedure.
+
+
+ OTP-19637 Application(s): ssh
+ Related Id(s): GH-6463, PR-9838
+
+ Improved interoperability with clients acting as
+ Paramiko.
+
+
+ Full runtime dependencies of ssh-5.1.4.10: crypto-5.0, erts-14.0,
+ kernel-9.0, public_key-1.6.1, runtime_tools-1.15.1, stdlib-5.0,
+ stdlib-5.0
+
+
+ ---------------------------------------------------------------------
+ --- stdlib-5.2.3.4 --------------------------------------------------
+ ---------------------------------------------------------------------
+
+ The stdlib-5.2.3.4 application can be applied independently of other
+ applications on a full OTP 26 installation.
+
+ --- Fixed Bugs and Malfunctions ---
+
+ OTP-19649 Application(s): stdlib
+ Related Id(s): GH-9771, PR-9898
+
+ It's now possible to write lists:map(fun is_atom/1, [])
+ or lists:map(fun my_func/1, []), in the shell, instead
+ of lists:map(fun erlang:is_atom/1, []) or lists:map(fun
+ shell_default:my_func/1, []).
+
+
+ OTP-19653 Application(s): stdlib
+ Related Id(s): PR-9941, CVE-2025-4748
+
+ Properly strip the leading / and drive letter from
+ filepaths when zipping and unzipping archives.
+
+ Thanks to Wander Nauta for finding and responsibly
+ disclosing this vulnerability to the Erlang/OTP
+ project.
+
+
+ OTP-19667 Application(s): kernel, stdlib
+ Related Id(s): PR-9912
+
+ A remote shell can now exit by closing the input
+ stream, without terminating the remote node.
+
+
+ Full runtime dependencies of stdlib-5.2.3.4: compiler-5.0,
+ crypto-4.5, erts-13.1, kernel-9.0, sasl-3.0
+
+
+ ---------------------------------------------------------------------
+ --- Thanks to -------------------------------------------------------
+ ---------------------------------------------------------------------
+
+ Yaroslav Maslennikov
+
+
+ ---------------------------------------------------------------------
+ ---------------------------------------------------------------------
+ ---------------------------------------------------------------------
+