FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Erlang/OTP -- TLS denial of service using invalid certificate chains

Affected packages
23.2,4 <= erlang < 28.5.0.4,4
erlang-runtime27 < 27.3.4.15
erlang-runtime28 < 28.5.0.4
erlang-runtime29 < 29.0.4

Details

VuXML ID 445d3f14-89e1-11f1-b35c-4c526214c986
Discovery 2026-07-27
Entry 2026-07-27

https://github.com/erlang/otp/security/advisories/GHSA-r5jr-mq46-vmhw reports:

A TLS/DTLS peer can crash the remote node by sending a certificate chain containing two mutually cross-signed certificates in unordered form. When the receiving side attempts to build a valid chain path, it enters unbounded recursion between the two certificates (A issues B, B issues A) with no cycle detection or depth limit. The call stack and chain accumulator grow without bound until the process exhausts available memory and the BEAM node crashes.

References

CVE Name CVE-2026-58227
URL https://github.com/erlang/otp/security/advisories/GHSA-r5jr-mq46-vmhw