Skip to content

ssh: fix mlkem768x25519 hybrid shared secret encoding#11209

Merged
u3s merged 3 commits into
erlang:maintfrom
cole-christensen:fix/ssh-mlkem-hybrid-x25519-secret-encoding
Jun 22, 2026
Merged

ssh: fix mlkem768x25519 hybrid shared secret encoding#11209
u3s merged 3 commits into
erlang:maintfrom
cole-christensen:fix/ssh-mlkem-hybrid-x25519-secret-encoding

Conversation

@cole-christensen

@cole-christensen cole-christensen commented Jun 6, 2026

Copy link
Copy Markdown
Contributor

Closes #11208

Summary

mlkem768x25519-sha256 key exchange intermittently fails (~1 in 512 handshakes)
with incorrect signature on the peer. hybrid_common/4 reconstructed the
classical X25519 shared secret by taking the last ?X25519_PUBLICKEY_SIZE bytes
of its mpint encoding. Because mpint is minimal-length, a shared secret whose
most significant byte is 0x00 and whose next byte is < 0x80 encodes to a
31-byte payload, and "the last 32 bytes" then includes a byte of the 4-byte
length prefix (0x1f) in place of the genuine leading 0x00. The two peers hash
different octet strings, derive a different exchange hash H, and the signature
check fails.

This encodes the ECDH shared secret as a fixed-width big-endian octet string,
preserving leading zero bytes.
draft-ietf-sshm-mlkem-hybrid-kex
§2.4 specifies this encoding — the component secrets are hashed as fixed-length
big-endian byte arrays — and OpenSSH's kexmlkem768x25519.c matches it.

 hybrid_common(K_pq_secret, Curve, PeerPublic, MyPrivate) ->
     K_cl_secret = compute_key(ecdh, PeerPublic, MyPrivate, Curve),
-    K_cl_secret_mpint = <<?Empint(K_cl_secret)>>,
-    K_cl_secret_mpint_trim =
-        binary:part(K_cl_secret_mpint, byte_size(K_cl_secret_mpint), -?X25519_PUBLICKEY_SIZE),
-    crypto:hash(sha(Curve), <<K_pq_secret/binary, K_cl_secret_mpint_trim/binary>>).
+    K_cl_secret_fixed = <<K_cl_secret:(?X25519_PUBLICKEY_SIZE*8)/big-unsigned-integer>>,
+    crypto:hash(sha(Curve), <<K_pq_secret/binary, K_cl_secret_fixed/binary>>).

The new encoding is byte-for-byte identical to the old one in every case except
the previously-broken one, so it only changes behaviour where the handshake was
already failing.

Probability / impact

P(trigger) = P(secret[0]==0x00) × P(secret[1] < 0x80) = 1/256 × 1/2 =
1/512 ≈ 0.195% per mlkem768x25519-sha256 handshake. At any non-trivial
connection volume this is a frequent, hard-to-diagnose interop failure against
OpenSSH (which is correct).

Introduced in 95d0848c60 ("ssh: MLKEM kex ssh"), released in OTP-28.4.

Verification

  • Deterministic unit check (<<0,1,0:240>> → old code yields 1F01…, fixed
    yields 0001…). See linked issue.

  • Monte-Carlo: 300k random secrets, old-vs-fixed mismatch rate 0.194%, every
    mismatch satisfies secret[0]==0x00 ∧ secret[1] < 0x80.

  • End-to-end against OpenSSH 10.3p1, BOTH roles, with the hybrid code
    instrumented to count how many handshakes actually hit the trigger ("case C")
    so success is not luck-of-the-draw:

    Role Mode Trigger handshakes Failures
    OTP daemon ← OpenSSH client stock 20 20 (1:1)
    OTP daemon ← OpenSSH client fixed 45 0
    OTP client → OpenSSH sshd stock 21 21 (1:1)
    OTP client → OpenSSH sshd fixed 31 0
  • Regression test in the suite (ssh_algorithms_SUITE:mlkem768x25519_hybrid_secret_encoding):
    passes with the fix, fails against the stock encoding. Run via the supported
    framework: ts:run(ssh, ssh_algorithms_SUITE, mlkem768x25519_hybrid_secret_encoding, [batch])
    TEST COMPLETE, 1 ok, 0 failed.

  • Full ssh_algorithms_SUITE: TEST COMPLETE, 930 ok, 0 failed of 930

The classical X25519 part of the mlkem768x25519-sha256 hybrid key
exchange shared secret was reconstructed by taking the last 32 bytes of
the mpint encoding of the ECDH secret. mpint is a minimal-length
big-endian representation, so when the shared secret's most significant
byte is 0x00 and the following byte is < 0x80 the payload is only 31
bytes and "the last 32 bytes" pulls in a byte of the 4-byte length
prefix (0x1f) in place of the genuine leading 0x00.

hybrid_common/4 then hashes a different octet string than the peer
(e.g. OpenSSH), producing a different exchange hash H. The server signs
an H the client never computed, and the client aborts the connection
with "incorrect signature". This affects roughly 1 in 512 handshakes
(P[msb=0x00] * P[next<0x80] = 1/256 * 1/2).

Encode the ECDH shared secret as a fixed-width big-endian octet string
so a genuine leading 0x00 byte is preserved, matching the peer.

Add a regression test (ssh_algorithms_SUITE:mlkem768x25519_hybrid_secret_encoding)
that searches for an X25519 key pair whose ECDH secret triggers the
condition and asserts hybrid_common/4 hashes it as a fixed-width 32-byte
octet string. The test fails against the old code and passes with the fix.

Introduced in 95d0848 (ssh: MLKEM kex ssh); present since OTP-28.4.
@CLAassistant

CLAassistant commented Jun 6, 2026

Copy link
Copy Markdown

CLA assistant check
All committers have signed the CLA.

@github-actions

github-actions Bot commented Jun 6, 2026

Copy link
Copy Markdown
Contributor

CT Test Results

    2 files     29 suites   28m 54s ⏱️
  506 tests   499 ✅  7 💤 0 ❌
1 715 runs  1 686 ✅ 29 💤 0 ❌

Results for commit 20ce349.

♻️ This comment has been updated with latest results.

To speed up review, make sure that you have read Contributing to Erlang/OTP and that all checks pass.

See the TESTING and DEVELOPMENT HowTo guides for details about how to run test locally.

Artifacts

// Erlang/OTP Github Action Bot

@Mikaka27 Mikaka27 added team:PS Assigned to OTP team PS testing currently being tested, tag is used by OTP internal CI labels Jun 7, 2026
@u3s u3s self-assigned this Jun 9, 2026
Add init_per_testcase guard for mlkem768x25519_hybrid_secret_encoding
that checks crypto:supports(curves) for x25519 and crypto:supports(kems)
for mlkem768 before running the test.

Without this, the test crashes with {badmatch,notsup} on platforms where
the crypto backend lacks X25519 or ML-KEM768 support.
@u3s u3s added testing currently being tested, tag is used by OTP internal CI and removed testing currently being tested, tag is used by OTP internal CI labels Jun 12, 2026
@u3s u3s added testing currently being tested, tag is used by OTP internal CI and removed testing currently being tested, tag is used by OTP internal CI labels Jun 15, 2026
@u3s
u3s merged commit dd6812f into erlang:maint Jun 22, 2026
31 checks passed
jimsynz pushed a commit to jimsynz/heap that referenced this pull request Jul 8, 2026
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [erlang](https://github.com/erlang/otp) | patch | `29.0.2` → `29.0.3` |

---

### Release Notes

<details>
<summary>erlang/otp (erlang)</summary>

### [`v29.0.3`](https://github.com/erlang/otp/releases/tag/OTP-29.0.3): OTP 29.0.3

[Compare Source](erlang/otp@OTP-29.0.2...OTP-29.0.3)

```
Patch Package:           OTP 29.0.3
Git Tag:                 OTP-29.0.3
Date:                    2026-07-02
Trouble Report Id:       OTP-20173, OTP-20183, OTP-20185, OTP-20186,
                         OTP-20190, OTP-20191, OTP-20194, OTP-20196,
                         OTP-20197, OTP-20198, OTP-20199, OTP-20200,
                         OTP-20201, OTP-20206, OTP-20207, OTP-20208,
                         OTP-20215, OTP-20216, OTP-20217, OTP-20220,
                         OTP-20222, OTP-20226, OTP-20227, OTP-20230,
                         OTP-20231, OTP-20232, OTP-20233
Seq num:                 CVE-2026-53422, CVE-2026-54886,
                         CVE-2026-54887, CVE-2026-54891,
                         CVE-2026-55950, CVE-2026-55952, ERIERL-1333,
                         GH-SA-7wp4-pc27-2vj9, GH-SA-h9pw-h5w4-h976,
                         PR-11209, PR-11215, PR-11219, PR-11230,
                         PR-11239, PR-11244, PR-11247, PR-11250,
                         PR-11259, PR-11268, PR-11269, PR-11270,
                         PR-11271, PR-11281, PR-11282, PR-11283,
                         PR-11289, PR-11294, PR-11295, PR-11299,
                         PR-11302, PR-11306, PR-11307, PR-11309,
                         PR-11311
System:                  OTP
Release:                 29
Application:             common_test-1.31.1, compiler-10.0.2,
                         crypto-5.9.1, dialyzer-6.0.2, erts-17.0.3,
                         kernel-11.0.3, public_key-1.21.3, ssh-6.0.2,
                         ssl-11.7.3, stdlib-8.0.2
Predecessor:             OTP 29.0.2
```

Check out the git tag OTP-29.0.3, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp\_patch\_apply' tool. For information on install requirements, see descriptions for each application version below.

### common\_test-1.31.1

The common\_test-1.31.1 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Fixed a crash in ct\_netconfc that occurred when the remote server closed the SSH connection during NETCONF subsystem negotiation.

  Own Id: OTP-20191\
  Related Id(s): ERIERL-1333, [PR-11230]

> #### Full runtime dependencies of common\_test-1.31.1
>
> compiler-10.0, crypto-4.5, debugger-4.1, erts-7.0, ftp-1.0, inets-6.0, kernel-11.0, observer-2.1, runtime\_tools-1.8.16, sasl-2.5, snmp-5.1.2, ssh-4.0, stdlib-8.0, syntax\_tools-1.7, tools-3.2, xmerl-1.3.8

### compiler-10.0.2

The compiler-10.0.2 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Several compiler bugs that could crash the compiler or generate incorrect code in rare circumstances have been fixed.

  Own Id: OTP-20222\
  Related Id(s): [PR-11219]

> #### Full runtime dependencies of compiler-10.0.2
>
> crypto-5.1, erts-13.0, kernel-8.4, stdlib-8.0

### crypto-5.9.1

The crypto-5.9.1 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- `crypto:compute_key/4` for `eddh` and `crypto:generate_key/2,3` for `eddh`/`eddsa` now raise an `error:{notsup, Info, Description}` exception instead of returning the atom `notsup` when the underlying cryptolib lacks support.

  Own Id: OTP-20215\
  Related Id(s): [PR-11302]

> #### Full runtime dependencies of crypto-5.9.1
>
> erts-9.0, kernel-6.0, stdlib-3.9

### dialyzer-6.0.2

The dialyzer-6.0.2 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Fix a bug with native record sets in `erl_types.erl`

  Own Id: OTP-20201

> #### Full runtime dependencies of dialyzer-6.0.2
>
> compiler-10.0, erts-12.0, kernel-8.0, stdlib-5.0, syntax\_tools-2.0

### erts-17.0.3

The erts-17.0.3 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Fixed an undefined behavior in the internal `erts_qsort()` function, which could have been the cause of a beam crash seen when updating large maps.

  Own Id: OTP-20185\
  Related Id(s): [PR-11215]

- Calculating `bxor` of the largest supported positive integer (`erlang:system_info(max_integer)`) and `-1` would return `[]` instead of a raising a `system_limit` exception.

  Own Id: OTP-20208\
  Related Id(s): [PR-11269]

- Fix possible race between `ets:delete/1` and terminating process with a fixation on the same table.

  Own Id: OTP-20217\
  Related Id(s): [PR-11283]

- A few code generation issues for the JIT on AArch64 (ARM64) have been fixed.

  For all platforms, the loader will reject some invalid BEAM files earlier.

  Own Id: OTP-20226\
  Related Id(s): [PR-11299]

- On 32-bit computers, the `md5` BIFs would return an incorrect MD5 checksum for data of size 4GiB or more.

  Own Id: OTP-20227\
  Related Id(s): [PR-11289]

> #### Full runtime dependencies of erts-17.0.3
>
> kernel-9.0, sasl-3.3, stdlib-4.1

### kernel-11.0.3

The kernel-11.0.3 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- inet:info/1 could crash when calling for a closing (port) socket.

  Own Id: OTP-20173

- Handling of the truncation bit in `inet_res` has been fixed so it properly falls back to querying over TCP after a truncated UDP reply.

  This fixes a bug introduced in OTP-28.4.2 - kernel-10.6.2 making a truncated UDP answer fail to parse and never execute the fallback, instead the name resolve operation fails.

  Own Id: OTP-20199\
  Related Id(s): [PR-11247]

> #### Full runtime dependencies of kernel-11.0.3
>
> crypto-5.8, erts-17.0, sasl-3.0, stdlib-8.0

### public\_key-1.21.3

The public\_key-1.21.3 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Hardened OCSP response verification by using constant-time hash comparisons and rejecting responses exceeding 100 KB before ASN.1 decoding.

  Own Id: OTP-20197\
  Related Id(s): [PR-11239]

> #### Full runtime dependencies of public\_key-1.21.3
>
> asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0

### ssh-6.0.2

The ssh-6.0.2 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Fixed a path-existence oracle in the SFTP server where `SSH_FXP_REALPATH` requests with `..` components could bypass the configured root directory isolation, allowing an authenticated client to determine whether arbitrary paths exist on the host filesystem.

  Own Id: OTP-20183\
  Related Id(s): [GH-SA-h9pw-h5w4-h976], [PR-11294], [CVE-2026-53422]

- Fixed an infinite loop in the SFTP server triggered when receiving `SSH_MSG_CHANNEL_EXTENDED_DATA` on an SFTP channel, which caused the channel process to spin indefinitely on CPU without consuming its message queue.

  Own Id: OTP-20186\
  Related Id(s): [GH-SA-7wp4-pc27-2vj9], [PR-11295], [CVE-2026-54886]

- Fixed mlkem768x25519 hybrid key exchange failing intermittently with "incorrect signature" when the X25519 shared secret had a leading zero byte. The shared secret is now encoded as a fixed-width 32-byte string per the specification.

  Own Id: OTP-20196\
  Related Id(s): [PR-11209]

- Fixed a race condition where SSH keepalive responses could be matched to unrelated pending requests due to incorrect request queue ordering. Requests are now matched in the order they were sent.

  Own Id: OTP-20198\
  Related Id(s): [PR-11244]

- The SFTP server now caps the read length in `SSH_FXP_READ` requests to 255 KiB (matching OpenSSH's `SFTP_MAX_READ_LENGTH`), preventing excessive memory allocation when clients request large reads.

  Own Id: OTP-20200\
  Related Id(s): [PR-11259]

- Removed a server-side workaround (OTP-14827, introduced in OTP 20) that accepted SHA-1 user-auth signatures from clients identifying as OpenSSH 7.x when rsa-sha2-\* was negotiated. The workaround addressed a distro-specific build issue in 2017 that no longer exists. Clients affected by this removal (extremely unlikely — requires a 10-year-old unpatched OpenSSH build) will see authentication failures and must upgrade.

  Own Id: OTP-20206\
  Related Id(s): [PR-11268]

> #### Full runtime dependencies of ssh-6.0.2
>
> crypto-5.7, erts-14.0, kernel-10.3, public\_key-1.6.1, runtime\_tools-1.15.1, stdlib-8.0

### ssl-11.7.3

Note! The ssl-11.7.3 application *cannot* be applied independently of other applications on an arbitrary OTP 29 installation.

```
   On a full OTP 29 installation, also the following runtime
   dependency has to be satisfied:
   -- public_key-1.21.1 (first satisfied in OTP 29.0.1)
```

#### Fixed Bugs and Malfunctions

- Correct small behavior bugs that occasionally could cause DTLS connection errors, unwanted behavior for legacy DHE\_DSS, hiding of a distribution config error, and possible unorderly process tree shutdown.

  Own Id: OTP-20190\
  Related Id(s): [PR-11250]

- Initialize DTLS cookie to random value to avoid DoS attack with forged cookie during startup window.

  Own Id: OTP-20194\
  Related Id(s): [PR-11271], [CVE-2026-54887]

- Guard TLS client for MITM injection of application data during "plain-text-window" during handshake.

  Own Id: OTP-20207\
  Related Id(s): [PR-11270], [CVE-2026-54891]

- Improve error handling of TLS PSK sending ILLIGAL\_PARMETER alert if binders and PSK-identities are not matched. Also mend recovery mechanism of ticket and session stores to be as resilient as possible to intermediate bugs.

  Own Id: OTP-20216\
  Related Id(s): [PR-11282], [CVE-2026-55952]

- Fix race condition that could be used to DoS attack DTLS servers.

  Own Id: OTP-20220\
  Related Id(s): [PR-11306], [CVE-2026-55950]

- A TLS-1.3 stateless session ticket with obfuscated\_ticket\_age set to zero was incorrectly accepted without checking the server-side ticket lifetime or the RFC 8446 Section 8.3 freshness window. The server now always validates ticket age using its own timestamp regardless of the client-reported age value.

  Own Id: OTP-20230\
  Related Id(s): [PR-11307]

- TLS-1.3 client rejects a second HelloRetryRequest as requiered in RFC 8446 Section 4.1.4

  Own Id: OTP-20231\
  Related Id(s): [PR-11309]

- A busy client node could self-trigger a ticket store crash if unlucky with scheduling if auto mode is used.

  Own Id: OTP-20232\
  Related Id(s): [PR-11311]

- Correct spec for CRL API

  Own Id: OTP-20233\
  Related Id(s): [PR-11281]

> #### Full runtime dependencies of ssl-11.7.3
>
> crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public\_key-1.21.1, runtime\_tools-1.15.1, stdlib-7.0

### stdlib-8.0.2

The stdlib-8.0.2 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Several compiler bugs that could crash the compiler or generate incorrect code in rare circumstances have been fixed.

  Own Id: OTP-20222\
  Related Id(s): [PR-11219]

> #### Full runtime dependencies of stdlib-8.0.2
>
> compiler-5.0, crypto-4.5, erts-16.0.3, kernel-11.0, sasl-3.0, syntax\_tools-3.2.1

### Thanks to

Cole Christensen, Nick Krichevsky, Stefan Grundmann

[cve-2026-53422]: https://nvd.nist.gov/vuln/detail/CVE-2026-53422

[cve-2026-54886]: https://nvd.nist.gov/vuln/detail/CVE-2026-54886

[cve-2026-54887]: https://nvd.nist.gov/vuln/detail/CVE-2026-54887

[cve-2026-54891]: https://nvd.nist.gov/vuln/detail/CVE-2026-54891

[cve-2026-55950]: https://nvd.nist.gov/vuln/detail/CVE-2026-55950

[cve-2026-55952]: https://nvd.nist.gov/vuln/detail/CVE-2026-55952

[gh-sa-7wp4-pc27-2vj9]: https://github.com/erlang/otp/issues/SA-7wp4-pc27-2vj9

[gh-sa-h9pw-h5w4-h976]: https://github.com/erlang/otp/issues/SA-h9pw-h5w4-h976

[pr-11209]: erlang/otp#11209

[pr-11215]: erlang/otp#11215

[pr-11219]: erlang/otp#11219

[pr-11230]: erlang/otp#11230

[pr-11239]: erlang/otp#11239

[pr-11244]: erlang/otp#11244

[pr-11247]: erlang/otp#11247

[pr-11250]: erlang/otp#11250

[pr-11259]: erlang/otp#11259

[pr-11268]: erlang/otp#11268

[pr-11269]: erlang/otp#11269

[pr-11270]: erlang/otp#11270

[pr-11271]: erlang/otp#11271

[pr-11281]: erlang/otp#11281

[pr-11282]: erlang/otp#11282

[pr-11283]: erlang/otp#11283

[pr-11289]: erlang/otp#11289

[pr-11294]: erlang/otp#11294

[pr-11295]: erlang/otp#11295

[pr-11299]: erlang/otp#11299

[pr-11302]: erlang/otp#11302

[pr-11306]: erlang/otp#11306

[pr-11307]: erlang/otp#11307

[pr-11309]: erlang/otp#11309

[pr-11311]: erlang/otp#11311

</details>

---

### Configuration

📅 **Schedule**: (in timezone Pacific/Auckland)

- Branch creation
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
- Automerge
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [x] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTIuNSIsInVwZGF0ZWRJblZlciI6IjQzLjI1Mi41IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

Reviewed-on: https://harton.dev/james/heap/pulls/156
jimsynz pushed a commit to jimsynz/wafer that referenced this pull request Jul 8, 2026
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [erlang](https://github.com/erlang/otp) | patch | `29.0.2` → `29.0.3` |

---

### Release Notes

<details>
<summary>erlang/otp (erlang)</summary>

### [`v29.0.3`](https://github.com/erlang/otp/releases/tag/OTP-29.0.3): OTP 29.0.3

[Compare Source](erlang/otp@OTP-29.0.2...OTP-29.0.3)

```
Patch Package:           OTP 29.0.3
Git Tag:                 OTP-29.0.3
Date:                    2026-07-02
Trouble Report Id:       OTP-20173, OTP-20183, OTP-20185, OTP-20186,
                         OTP-20190, OTP-20191, OTP-20194, OTP-20196,
                         OTP-20197, OTP-20198, OTP-20199, OTP-20200,
                         OTP-20201, OTP-20206, OTP-20207, OTP-20208,
                         OTP-20215, OTP-20216, OTP-20217, OTP-20220,
                         OTP-20222, OTP-20226, OTP-20227, OTP-20230,
                         OTP-20231, OTP-20232, OTP-20233
Seq num:                 CVE-2026-53422, CVE-2026-54886,
                         CVE-2026-54887, CVE-2026-54891,
                         CVE-2026-55950, CVE-2026-55952, ERIERL-1333,
                         GH-SA-7wp4-pc27-2vj9, GH-SA-h9pw-h5w4-h976,
                         PR-11209, PR-11215, PR-11219, PR-11230,
                         PR-11239, PR-11244, PR-11247, PR-11250,
                         PR-11259, PR-11268, PR-11269, PR-11270,
                         PR-11271, PR-11281, PR-11282, PR-11283,
                         PR-11289, PR-11294, PR-11295, PR-11299,
                         PR-11302, PR-11306, PR-11307, PR-11309,
                         PR-11311
System:                  OTP
Release:                 29
Application:             common_test-1.31.1, compiler-10.0.2,
                         crypto-5.9.1, dialyzer-6.0.2, erts-17.0.3,
                         kernel-11.0.3, public_key-1.21.3, ssh-6.0.2,
                         ssl-11.7.3, stdlib-8.0.2
Predecessor:             OTP 29.0.2
```

Check out the git tag OTP-29.0.3, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp\_patch\_apply' tool. For information on install requirements, see descriptions for each application version below.

### common\_test-1.31.1

The common\_test-1.31.1 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Fixed a crash in ct\_netconfc that occurred when the remote server closed the SSH connection during NETCONF subsystem negotiation.

  Own Id: OTP-20191\
  Related Id(s): ERIERL-1333, [PR-11230]

> #### Full runtime dependencies of common\_test-1.31.1
>
> compiler-10.0, crypto-4.5, debugger-4.1, erts-7.0, ftp-1.0, inets-6.0, kernel-11.0, observer-2.1, runtime\_tools-1.8.16, sasl-2.5, snmp-5.1.2, ssh-4.0, stdlib-8.0, syntax\_tools-1.7, tools-3.2, xmerl-1.3.8

### compiler-10.0.2

The compiler-10.0.2 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Several compiler bugs that could crash the compiler or generate incorrect code in rare circumstances have been fixed.

  Own Id: OTP-20222\
  Related Id(s): [PR-11219]

> #### Full runtime dependencies of compiler-10.0.2
>
> crypto-5.1, erts-13.0, kernel-8.4, stdlib-8.0

### crypto-5.9.1

The crypto-5.9.1 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- `crypto:compute_key/4` for `eddh` and `crypto:generate_key/2,3` for `eddh`/`eddsa` now raise an `error:{notsup, Info, Description}` exception instead of returning the atom `notsup` when the underlying cryptolib lacks support.

  Own Id: OTP-20215\
  Related Id(s): [PR-11302]

> #### Full runtime dependencies of crypto-5.9.1
>
> erts-9.0, kernel-6.0, stdlib-3.9

### dialyzer-6.0.2

The dialyzer-6.0.2 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Fix a bug with native record sets in `erl_types.erl`

  Own Id: OTP-20201

> #### Full runtime dependencies of dialyzer-6.0.2
>
> compiler-10.0, erts-12.0, kernel-8.0, stdlib-5.0, syntax\_tools-2.0

### erts-17.0.3

The erts-17.0.3 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Fixed an undefined behavior in the internal `erts_qsort()` function, which could have been the cause of a beam crash seen when updating large maps.

  Own Id: OTP-20185\
  Related Id(s): [PR-11215]

- Calculating `bxor` of the largest supported positive integer (`erlang:system_info(max_integer)`) and `-1` would return `[]` instead of a raising a `system_limit` exception.

  Own Id: OTP-20208\
  Related Id(s): [PR-11269]

- Fix possible race between `ets:delete/1` and terminating process with a fixation on the same table.

  Own Id: OTP-20217\
  Related Id(s): [PR-11283]

- A few code generation issues for the JIT on AArch64 (ARM64) have been fixed.

  For all platforms, the loader will reject some invalid BEAM files earlier.

  Own Id: OTP-20226\
  Related Id(s): [PR-11299]

- On 32-bit computers, the `md5` BIFs would return an incorrect MD5 checksum for data of size 4GiB or more.

  Own Id: OTP-20227\
  Related Id(s): [PR-11289]

> #### Full runtime dependencies of erts-17.0.3
>
> kernel-9.0, sasl-3.3, stdlib-4.1

### kernel-11.0.3

The kernel-11.0.3 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- inet:info/1 could crash when calling for a closing (port) socket.

  Own Id: OTP-20173

- Handling of the truncation bit in `inet_res` has been fixed so it properly falls back to querying over TCP after a truncated UDP reply.

  This fixes a bug introduced in OTP-28.4.2 - kernel-10.6.2 making a truncated UDP answer fail to parse and never execute the fallback, instead the name resolve operation fails.

  Own Id: OTP-20199\
  Related Id(s): [PR-11247]

> #### Full runtime dependencies of kernel-11.0.3
>
> crypto-5.8, erts-17.0, sasl-3.0, stdlib-8.0

### public\_key-1.21.3

The public\_key-1.21.3 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Hardened OCSP response verification by using constant-time hash comparisons and rejecting responses exceeding 100 KB before ASN.1 decoding.

  Own Id: OTP-20197\
  Related Id(s): [PR-11239]

> #### Full runtime dependencies of public\_key-1.21.3
>
> asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0

### ssh-6.0.2

The ssh-6.0.2 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Fixed a path-existence oracle in the SFTP server where `SSH_FXP_REALPATH` requests with `..` components could bypass the configured root directory isolation, allowing an authenticated client to determine whether arbitrary paths exist on the host filesystem.

  Own Id: OTP-20183\
  Related Id(s): [GH-SA-h9pw-h5w4-h976], [PR-11294], [CVE-2026-53422]

- Fixed an infinite loop in the SFTP server triggered when receiving `SSH_MSG_CHANNEL_EXTENDED_DATA` on an SFTP channel, which caused the channel process to spin indefinitely on CPU without consuming its message queue.

  Own Id: OTP-20186\
  Related Id(s): [GH-SA-7wp4-pc27-2vj9], [PR-11295], [CVE-2026-54886]

- Fixed mlkem768x25519 hybrid key exchange failing intermittently with "incorrect signature" when the X25519 shared secret had a leading zero byte. The shared secret is now encoded as a fixed-width 32-byte string per the specification.

  Own Id: OTP-20196\
  Related Id(s): [PR-11209]

- Fixed a race condition where SSH keepalive responses could be matched to unrelated pending requests due to incorrect request queue ordering. Requests are now matched in the order they were sent.

  Own Id: OTP-20198\
  Related Id(s): [PR-11244]

- The SFTP server now caps the read length in `SSH_FXP_READ` requests to 255 KiB (matching OpenSSH's `SFTP_MAX_READ_LENGTH`), preventing excessive memory allocation when clients request large reads.

  Own Id: OTP-20200\
  Related Id(s): [PR-11259]

- Removed a server-side workaround (OTP-14827, introduced in OTP 20) that accepted SHA-1 user-auth signatures from clients identifying as OpenSSH 7.x when rsa-sha2-\* was negotiated. The workaround addressed a distro-specific build issue in 2017 that no longer exists. Clients affected by this removal (extremely unlikely — requires a 10-year-old unpatched OpenSSH build) will see authentication failures and must upgrade.

  Own Id: OTP-20206\
  Related Id(s): [PR-11268]

> #### Full runtime dependencies of ssh-6.0.2
>
> crypto-5.7, erts-14.0, kernel-10.3, public\_key-1.6.1, runtime\_tools-1.15.1, stdlib-8.0

### ssl-11.7.3

Note! The ssl-11.7.3 application *cannot* be applied independently of other applications on an arbitrary OTP 29 installation.

```
   On a full OTP 29 installation, also the following runtime
   dependency has to be satisfied:
   -- public_key-1.21.1 (first satisfied in OTP 29.0.1)
```

#### Fixed Bugs and Malfunctions

- Correct small behavior bugs that occasionally could cause DTLS connection errors, unwanted behavior for legacy DHE\_DSS, hiding of a distribution config error, and possible unorderly process tree shutdown.

  Own Id: OTP-20190\
  Related Id(s): [PR-11250]

- Initialize DTLS cookie to random value to avoid DoS attack with forged cookie during startup window.

  Own Id: OTP-20194\
  Related Id(s): [PR-11271], [CVE-2026-54887]

- Guard TLS client for MITM injection of application data during "plain-text-window" during handshake.

  Own Id: OTP-20207\
  Related Id(s): [PR-11270], [CVE-2026-54891]

- Improve error handling of TLS PSK sending ILLIGAL\_PARMETER alert if binders and PSK-identities are not matched. Also mend recovery mechanism of ticket and session stores to be as resilient as possible to intermediate bugs.

  Own Id: OTP-20216\
  Related Id(s): [PR-11282], [CVE-2026-55952]

- Fix race condition that could be used to DoS attack DTLS servers.

  Own Id: OTP-20220\
  Related Id(s): [PR-11306], [CVE-2026-55950]

- A TLS-1.3 stateless session ticket with obfuscated\_ticket\_age set to zero was incorrectly accepted without checking the server-side ticket lifetime or the RFC 8446 Section 8.3 freshness window. The server now always validates ticket age using its own timestamp regardless of the client-reported age value.

  Own Id: OTP-20230\
  Related Id(s): [PR-11307]

- TLS-1.3 client rejects a second HelloRetryRequest as requiered in RFC 8446 Section 4.1.4

  Own Id: OTP-20231\
  Related Id(s): [PR-11309]

- A busy client node could self-trigger a ticket store crash if unlucky with scheduling if auto mode is used.

  Own Id: OTP-20232\
  Related Id(s): [PR-11311]

- Correct spec for CRL API

  Own Id: OTP-20233\
  Related Id(s): [PR-11281]

> #### Full runtime dependencies of ssl-11.7.3
>
> crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public\_key-1.21.1, runtime\_tools-1.15.1, stdlib-7.0

### stdlib-8.0.2

The stdlib-8.0.2 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Several compiler bugs that could crash the compiler or generate incorrect code in rare circumstances have been fixed.

  Own Id: OTP-20222\
  Related Id(s): [PR-11219]

> #### Full runtime dependencies of stdlib-8.0.2
>
> compiler-5.0, crypto-4.5, erts-16.0.3, kernel-11.0, sasl-3.0, syntax\_tools-3.2.1

### Thanks to

Cole Christensen, Nick Krichevsky, Stefan Grundmann

[cve-2026-53422]: https://nvd.nist.gov/vuln/detail/CVE-2026-53422

[cve-2026-54886]: https://nvd.nist.gov/vuln/detail/CVE-2026-54886

[cve-2026-54887]: https://nvd.nist.gov/vuln/detail/CVE-2026-54887

[cve-2026-54891]: https://nvd.nist.gov/vuln/detail/CVE-2026-54891

[cve-2026-55950]: https://nvd.nist.gov/vuln/detail/CVE-2026-55950

[cve-2026-55952]: https://nvd.nist.gov/vuln/detail/CVE-2026-55952

[gh-sa-7wp4-pc27-2vj9]: https://github.com/erlang/otp/issues/SA-7wp4-pc27-2vj9

[gh-sa-h9pw-h5w4-h976]: https://github.com/erlang/otp/issues/SA-h9pw-h5w4-h976

[pr-11209]: erlang/otp#11209

[pr-11215]: erlang/otp#11215

[pr-11219]: erlang/otp#11219

[pr-11230]: erlang/otp#11230

[pr-11239]: erlang/otp#11239

[pr-11244]: erlang/otp#11244

[pr-11247]: erlang/otp#11247

[pr-11250]: erlang/otp#11250

[pr-11259]: erlang/otp#11259

[pr-11268]: erlang/otp#11268

[pr-11269]: erlang/otp#11269

[pr-11270]: erlang/otp#11270

[pr-11271]: erlang/otp#11271

[pr-11281]: erlang/otp#11281

[pr-11282]: erlang/otp#11282

[pr-11283]: erlang/otp#11283

[pr-11289]: erlang/otp#11289

[pr-11294]: erlang/otp#11294

[pr-11295]: erlang/otp#11295

[pr-11299]: erlang/otp#11299

[pr-11302]: erlang/otp#11302

[pr-11306]: erlang/otp#11306

[pr-11307]: erlang/otp#11307

[pr-11309]: erlang/otp#11309

[pr-11311]: erlang/otp#11311

</details>

---

### Configuration

📅 **Schedule**: (in timezone Pacific/Auckland)

- Branch creation
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
- Automerge
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTIuNSIsInVwZGF0ZWRJblZlciI6IjQzLjI1Mi41IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

Reviewed-on: https://harton.dev/james/wafer/pulls/202
jimsynz pushed a commit to jimsynz/ash_cubdb that referenced this pull request Jul 8, 2026
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [erlang](https://github.com/erlang/otp) | patch | `29.0.2` → `29.0.3` |

---

### Release Notes

<details>
<summary>erlang/otp (erlang)</summary>

### [`v29.0.3`](https://github.com/erlang/otp/releases/tag/OTP-29.0.3): OTP 29.0.3

[Compare Source](erlang/otp@OTP-29.0.2...OTP-29.0.3)

```
Patch Package:           OTP 29.0.3
Git Tag:                 OTP-29.0.3
Date:                    2026-07-02
Trouble Report Id:       OTP-20173, OTP-20183, OTP-20185, OTP-20186,
                         OTP-20190, OTP-20191, OTP-20194, OTP-20196,
                         OTP-20197, OTP-20198, OTP-20199, OTP-20200,
                         OTP-20201, OTP-20206, OTP-20207, OTP-20208,
                         OTP-20215, OTP-20216, OTP-20217, OTP-20220,
                         OTP-20222, OTP-20226, OTP-20227, OTP-20230,
                         OTP-20231, OTP-20232, OTP-20233
Seq num:                 CVE-2026-53422, CVE-2026-54886,
                         CVE-2026-54887, CVE-2026-54891,
                         CVE-2026-55950, CVE-2026-55952, ERIERL-1333,
                         GH-SA-7wp4-pc27-2vj9, GH-SA-h9pw-h5w4-h976,
                         PR-11209, PR-11215, PR-11219, PR-11230,
                         PR-11239, PR-11244, PR-11247, PR-11250,
                         PR-11259, PR-11268, PR-11269, PR-11270,
                         PR-11271, PR-11281, PR-11282, PR-11283,
                         PR-11289, PR-11294, PR-11295, PR-11299,
                         PR-11302, PR-11306, PR-11307, PR-11309,
                         PR-11311
System:                  OTP
Release:                 29
Application:             common_test-1.31.1, compiler-10.0.2,
                         crypto-5.9.1, dialyzer-6.0.2, erts-17.0.3,
                         kernel-11.0.3, public_key-1.21.3, ssh-6.0.2,
                         ssl-11.7.3, stdlib-8.0.2
Predecessor:             OTP 29.0.2
```

Check out the git tag OTP-29.0.3, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp\_patch\_apply' tool. For information on install requirements, see descriptions for each application version below.

### common\_test-1.31.1

The common\_test-1.31.1 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Fixed a crash in ct\_netconfc that occurred when the remote server closed the SSH connection during NETCONF subsystem negotiation.

  Own Id: OTP-20191\
  Related Id(s): ERIERL-1333, [PR-11230]

> #### Full runtime dependencies of common\_test-1.31.1
>
> compiler-10.0, crypto-4.5, debugger-4.1, erts-7.0, ftp-1.0, inets-6.0, kernel-11.0, observer-2.1, runtime\_tools-1.8.16, sasl-2.5, snmp-5.1.2, ssh-4.0, stdlib-8.0, syntax\_tools-1.7, tools-3.2, xmerl-1.3.8

### compiler-10.0.2

The compiler-10.0.2 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Several compiler bugs that could crash the compiler or generate incorrect code in rare circumstances have been fixed.

  Own Id: OTP-20222\
  Related Id(s): [PR-11219]

> #### Full runtime dependencies of compiler-10.0.2
>
> crypto-5.1, erts-13.0, kernel-8.4, stdlib-8.0

### crypto-5.9.1

The crypto-5.9.1 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- `crypto:compute_key/4` for `eddh` and `crypto:generate_key/2,3` for `eddh`/`eddsa` now raise an `error:{notsup, Info, Description}` exception instead of returning the atom `notsup` when the underlying cryptolib lacks support.

  Own Id: OTP-20215\
  Related Id(s): [PR-11302]

> #### Full runtime dependencies of crypto-5.9.1
>
> erts-9.0, kernel-6.0, stdlib-3.9

### dialyzer-6.0.2

The dialyzer-6.0.2 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Fix a bug with native record sets in `erl_types.erl`

  Own Id: OTP-20201

> #### Full runtime dependencies of dialyzer-6.0.2
>
> compiler-10.0, erts-12.0, kernel-8.0, stdlib-5.0, syntax\_tools-2.0

### erts-17.0.3

The erts-17.0.3 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Fixed an undefined behavior in the internal `erts_qsort()` function, which could have been the cause of a beam crash seen when updating large maps.

  Own Id: OTP-20185\
  Related Id(s): [PR-11215]

- Calculating `bxor` of the largest supported positive integer (`erlang:system_info(max_integer)`) and `-1` would return `[]` instead of a raising a `system_limit` exception.

  Own Id: OTP-20208\
  Related Id(s): [PR-11269]

- Fix possible race between `ets:delete/1` and terminating process with a fixation on the same table.

  Own Id: OTP-20217\
  Related Id(s): [PR-11283]

- A few code generation issues for the JIT on AArch64 (ARM64) have been fixed.

  For all platforms, the loader will reject some invalid BEAM files earlier.

  Own Id: OTP-20226\
  Related Id(s): [PR-11299]

- On 32-bit computers, the `md5` BIFs would return an incorrect MD5 checksum for data of size 4GiB or more.

  Own Id: OTP-20227\
  Related Id(s): [PR-11289]

> #### Full runtime dependencies of erts-17.0.3
>
> kernel-9.0, sasl-3.3, stdlib-4.1

### kernel-11.0.3

The kernel-11.0.3 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- inet:info/1 could crash when calling for a closing (port) socket.

  Own Id: OTP-20173

- Handling of the truncation bit in `inet_res` has been fixed so it properly falls back to querying over TCP after a truncated UDP reply.

  This fixes a bug introduced in OTP-28.4.2 - kernel-10.6.2 making a truncated UDP answer fail to parse and never execute the fallback, instead the name resolve operation fails.

  Own Id: OTP-20199\
  Related Id(s): [PR-11247]

> #### Full runtime dependencies of kernel-11.0.3
>
> crypto-5.8, erts-17.0, sasl-3.0, stdlib-8.0

### public\_key-1.21.3

The public\_key-1.21.3 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Hardened OCSP response verification by using constant-time hash comparisons and rejecting responses exceeding 100 KB before ASN.1 decoding.

  Own Id: OTP-20197\
  Related Id(s): [PR-11239]

> #### Full runtime dependencies of public\_key-1.21.3
>
> asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0

### ssh-6.0.2

The ssh-6.0.2 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Fixed a path-existence oracle in the SFTP server where `SSH_FXP_REALPATH` requests with `..` components could bypass the configured root directory isolation, allowing an authenticated client to determine whether arbitrary paths exist on the host filesystem.

  Own Id: OTP-20183\
  Related Id(s): [GH-SA-h9pw-h5w4-h976], [PR-11294], [CVE-2026-53422]

- Fixed an infinite loop in the SFTP server triggered when receiving `SSH_MSG_CHANNEL_EXTENDED_DATA` on an SFTP channel, which caused the channel process to spin indefinitely on CPU without consuming its message queue.

  Own Id: OTP-20186\
  Related Id(s): [GH-SA-7wp4-pc27-2vj9], [PR-11295], [CVE-2026-54886]

- Fixed mlkem768x25519 hybrid key exchange failing intermittently with "incorrect signature" when the X25519 shared secret had a leading zero byte. The shared secret is now encoded as a fixed-width 32-byte string per the specification.

  Own Id: OTP-20196\
  Related Id(s): [PR-11209]

- Fixed a race condition where SSH keepalive responses could be matched to unrelated pending requests due to incorrect request queue ordering. Requests are now matched in the order they were sent.

  Own Id: OTP-20198\
  Related Id(s): [PR-11244]

- The SFTP server now caps the read length in `SSH_FXP_READ` requests to 255 KiB (matching OpenSSH's `SFTP_MAX_READ_LENGTH`), preventing excessive memory allocation when clients request large reads.

  Own Id: OTP-20200\
  Related Id(s): [PR-11259]

- Removed a server-side workaround (OTP-14827, introduced in OTP 20) that accepted SHA-1 user-auth signatures from clients identifying as OpenSSH 7.x when rsa-sha2-\* was negotiated. The workaround addressed a distro-specific build issue in 2017 that no longer exists. Clients affected by this removal (extremely unlikely — requires a 10-year-old unpatched OpenSSH build) will see authentication failures and must upgrade.

  Own Id: OTP-20206\
  Related Id(s): [PR-11268]

> #### Full runtime dependencies of ssh-6.0.2
>
> crypto-5.7, erts-14.0, kernel-10.3, public\_key-1.6.1, runtime\_tools-1.15.1, stdlib-8.0

### ssl-11.7.3

Note! The ssl-11.7.3 application *cannot* be applied independently of other applications on an arbitrary OTP 29 installation.

```
   On a full OTP 29 installation, also the following runtime
   dependency has to be satisfied:
   -- public_key-1.21.1 (first satisfied in OTP 29.0.1)
```

#### Fixed Bugs and Malfunctions

- Correct small behavior bugs that occasionally could cause DTLS connection errors, unwanted behavior for legacy DHE\_DSS, hiding of a distribution config error, and possible unorderly process tree shutdown.

  Own Id: OTP-20190\
  Related Id(s): [PR-11250]

- Initialize DTLS cookie to random value to avoid DoS attack with forged cookie during startup window.

  Own Id: OTP-20194\
  Related Id(s): [PR-11271], [CVE-2026-54887]

- Guard TLS client for MITM injection of application data during "plain-text-window" during handshake.

  Own Id: OTP-20207\
  Related Id(s): [PR-11270], [CVE-2026-54891]

- Improve error handling of TLS PSK sending ILLIGAL\_PARMETER alert if binders and PSK-identities are not matched. Also mend recovery mechanism of ticket and session stores to be as resilient as possible to intermediate bugs.

  Own Id: OTP-20216\
  Related Id(s): [PR-11282], [CVE-2026-55952]

- Fix race condition that could be used to DoS attack DTLS servers.

  Own Id: OTP-20220\
  Related Id(s): [PR-11306], [CVE-2026-55950]

- A TLS-1.3 stateless session ticket with obfuscated\_ticket\_age set to zero was incorrectly accepted without checking the server-side ticket lifetime or the RFC 8446 Section 8.3 freshness window. The server now always validates ticket age using its own timestamp regardless of the client-reported age value.

  Own Id: OTP-20230\
  Related Id(s): [PR-11307]

- TLS-1.3 client rejects a second HelloRetryRequest as requiered in RFC 8446 Section 4.1.4

  Own Id: OTP-20231\
  Related Id(s): [PR-11309]

- A busy client node could self-trigger a ticket store crash if unlucky with scheduling if auto mode is used.

  Own Id: OTP-20232\
  Related Id(s): [PR-11311]

- Correct spec for CRL API

  Own Id: OTP-20233\
  Related Id(s): [PR-11281]

> #### Full runtime dependencies of ssl-11.7.3
>
> crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public\_key-1.21.1, runtime\_tools-1.15.1, stdlib-7.0

### stdlib-8.0.2

The stdlib-8.0.2 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Several compiler bugs that could crash the compiler or generate incorrect code in rare circumstances have been fixed.

  Own Id: OTP-20222\
  Related Id(s): [PR-11219]

> #### Full runtime dependencies of stdlib-8.0.2
>
> compiler-5.0, crypto-4.5, erts-16.0.3, kernel-11.0, sasl-3.0, syntax\_tools-3.2.1

### Thanks to

Cole Christensen, Nick Krichevsky, Stefan Grundmann

[cve-2026-53422]: https://nvd.nist.gov/vuln/detail/CVE-2026-53422

[cve-2026-54886]: https://nvd.nist.gov/vuln/detail/CVE-2026-54886

[cve-2026-54887]: https://nvd.nist.gov/vuln/detail/CVE-2026-54887

[cve-2026-54891]: https://nvd.nist.gov/vuln/detail/CVE-2026-54891

[cve-2026-55950]: https://nvd.nist.gov/vuln/detail/CVE-2026-55950

[cve-2026-55952]: https://nvd.nist.gov/vuln/detail/CVE-2026-55952

[gh-sa-7wp4-pc27-2vj9]: https://github.com/erlang/otp/issues/SA-7wp4-pc27-2vj9

[gh-sa-h9pw-h5w4-h976]: https://github.com/erlang/otp/issues/SA-h9pw-h5w4-h976

[pr-11209]: erlang/otp#11209

[pr-11215]: erlang/otp#11215

[pr-11219]: erlang/otp#11219

[pr-11230]: erlang/otp#11230

[pr-11239]: erlang/otp#11239

[pr-11244]: erlang/otp#11244

[pr-11247]: erlang/otp#11247

[pr-11250]: erlang/otp#11250

[pr-11259]: erlang/otp#11259

[pr-11268]: erlang/otp#11268

[pr-11269]: erlang/otp#11269

[pr-11270]: erlang/otp#11270

[pr-11271]: erlang/otp#11271

[pr-11281]: erlang/otp#11281

[pr-11282]: erlang/otp#11282

[pr-11283]: erlang/otp#11283

[pr-11289]: erlang/otp#11289

[pr-11294]: erlang/otp#11294

[pr-11295]: erlang/otp#11295

[pr-11299]: erlang/otp#11299

[pr-11302]: erlang/otp#11302

[pr-11306]: erlang/otp#11306

[pr-11307]: erlang/otp#11307

[pr-11309]: erlang/otp#11309

[pr-11311]: erlang/otp#11311

</details>

---

### Configuration

📅 **Schedule**: (in timezone Pacific/Auckland)

- Branch creation
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)
- Automerge
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTIuNSIsInVwZGF0ZWRJblZlciI6IjQzLjI1Mi41IiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

Reviewed-on: https://harton.dev/james/ash_cubdb/pulls/415
jimsynz added a commit to jimsynz/neonfs that referenced this pull request Jul 19, 2026
This PR contains the following updates:

| Package | Type | Update | Change |
|---|---|---|---|
| [actions/cache](https://github.com/actions/cache) | action | major | `v5` → `v6` |
| [actions/checkout](https://github.com/actions/checkout) | action | major | `v6` → `v7` |
| [aes-gcm](https://github.com/RustCrypto/AEADs) | dependencies | minor | `0.10` → `0.11` |
| debian | stage | patch | `trixie-20260610` → `13` |
| debian | final | patch | `trixie-20260610` → `13` |
| [elixir](https://elixir-lang.org/) ([source](https://github.com/elixir-lang/elixir)) |  | patch | `1.20.1` → `1.20.2` |
| [erlang](https://github.com/erlang/otp) |  | patch | `29.0.2` → `29.0.3` |
| [goreleaser/nfpm](https://github.com/goreleaser/nfpm) |  | minor | `v2.46.3` → `v2.47.0` |
| [ra](https://hex.pm/packages/ra) ([source](https://github.com/rabbitmq/ra)) | prod | patch | `3.1.8` → `3.1.9` |
| registry.k8s.io/sig-storage/csi-resizer |  | patch | `v2.2.0` → `v2.2.1` |
| [req](https://hex.pm/packages/req) ([source](https://github.com/wojtekmach/req)) | dev | patch | `0.6.2` → `0.6.3` |
| [req](https://hex.pm/packages/req) ([source](https://github.com/wojtekmach/req)) | dev | patch | `~> 0.5` → `~> 0.6` |
| [rust](https://github.com/rust-lang/rust) |  | minor | `1.96.0` → `1.97.1` |
| [serde](https://serde.rs) ([source](https://github.com/serde-rs/serde)) | dependencies | patch | `1.0.228` → `1.0.229` |
| [stream_data](https://hex.pm/packages/stream_data) ([source](https://github.com/whatyouhide/stream_data)) | dev | minor | `1.3.0` → `1.4.0` |
| [stream_data](https://hex.pm/packages/stream_data) ([source](https://github.com/whatyouhide/stream_data)) | prod | minor | `1.3.0` → `1.4.0` |
| [thiserror](https://github.com/dtolnay/thiserror) | dependencies | patch | `2.0.18` → `2.0.19` |

---

### Release Notes

<details>
<summary>actions/cache (actions/cache)</summary>

### [`v6.1.0`](https://github.com/actions/cache/releases/tag/v6.1.0)

[Compare Source](actions/cache@v6.0.0...v6.1.0)

##### What's Changed

- Bump [@&#8203;actions/cache](https://github.com/actions/cache) to v6.1.0 - handle read-only cache access by [@&#8203;jasongin](https://github.com/jasongin) in [#&#8203;1768](actions/cache#1768)

**Full Changelog**: <actions/cache@v6...v6.1.0>

### [`v6.0.0`](https://github.com/actions/cache/releases/tag/v6.0.0)

[Compare Source](actions/cache@v6.0.0...v6.0.0)

##### What's Changed

- Update packages, migrate to ESM by [@&#8203;Samirat](https://github.com/Samirat) in [#&#8203;1760](actions/cache#1760)

**Full Changelog**: <actions/cache@v5...v6.0.0>

### [`v6`](actions/cache@v5.1.0...v6.0.0)

[Compare Source](actions/cache@v5.1.0...v6.0.0)

</details>

<details>
<summary>actions/checkout (actions/checkout)</summary>

### [`v7.0.0`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v700)

[Compare Source](actions/checkout@v7.0.0...v7.0.0)

- Block checking out fork PR for pull\_request\_target and workflow\_run by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2454](actions/checkout#2454)
- Bump actions/publish-immutable-action from 0.0.3 to 0.0.4 in the minor-actions-dependencies group across 1 directory by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;2458](actions/checkout#2458)
- Bump flatted from 3.3.1 to 3.4.2 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;2460](actions/checkout#2460)
- Bump js-yaml from 4.1.0 to 4.2.0 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;2461](actions/checkout#2461)
- Bump [@&#8203;actions/core](https://github.com/actions/core) and [@&#8203;actions/tool-cache](https://github.com/actions/tool-cache) and Remove uuid by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;2459](actions/checkout#2459)
- upgrade module to esm and update dependencies by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2463](actions/checkout#2463)
- Bump the minor-npm-dependencies group across 1 directory with 3 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;2462](actions/checkout#2462)

### [`v7`](https://github.com/actions/checkout/blob/HEAD/CHANGELOG.md#v701)

[Compare Source](actions/checkout@v6.0.3...v7.0.0)

- Bump github/codeql-action from 3 to 4 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;2475](actions/checkout#2475)
- Bump actions/setup-node from 4 to 6 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;2477](actions/checkout#2477)
- Bump docker/build-push-action from 6.5.0 to 7.2.0 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;2478](actions/checkout#2478)
- Bump docker/login-action from 3.3.0 to 4.2.0 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;2479](actions/checkout#2479)
- Bump actions/checkout from 6 to 7 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;2488](actions/checkout#2488)
- Bump actions/upload-artifact from 4 to 7 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;2476](actions/checkout#2476)
- eslint 9 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;2474](actions/checkout#2474)
- Bump the minor-actions-dependencies group with 2 updates by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;2499](actions/checkout#2499)
- skip running unsafe pr check if input is default by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2518](actions/checkout#2518)
- trim only ascii whitespace for branch by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2521](actions/checkout#2521)
- escape values passed to --unset by [@&#8203;aiqiaoy](https://github.com/aiqiaoy) in [#&#8203;2530](actions/checkout#2530)

</details>

<details>
<summary>RustCrypto/AEADs (aes-gcm)</summary>

### [`v0.11.0`](RustCrypto/AEADs@aes-gcm-v0.10.3...aes-gcm-v0.11.0)

[Compare Source](RustCrypto/AEADs@aes-gcm-v0.10.3...aes-gcm-v0.11.0)

</details>

<details>
<summary>elixir-lang/elixir (elixir)</summary>

### [`v1.20.2`](https://github.com/elixir-lang/elixir/releases/tag/v1.20.2)

[Compare Source](elixir-lang/elixir@v1.20.1...v1.20.2)

##### 1. Enhancements

##### Elixir

- \[Kernel.ParallelCompiler] Include per-module type checking times when compiler profiling is enabled with `profile: :time`

##### 2. Bug fixes

##### Elixir

- \[Kernel] Fix binary comprehensions with sizes when options such as `:uniq` or `:into` are used
- \[Kernel] Improve compiler error messages when `quote` with `unquote` is used inside a pattern or guard
- \[Kernel] Restore the compiler optimization of `Kernel.put_elem/3` to emit `:erlang.setelement/3`
- \[Module] Fix type checking when applying an empty function type
- \[Module] Fix type checking of bitstring patterns that reuse variables
- \[Module] Fix type information for `__info__(:struct)` to include the `:required` key
- \[Module] Fix type operations on map and optional keys during difference/intersection, including open keys and empty intersections
- \[Module] Fix typing of list types involving dynamic or empty lists
- \[Module] Include bitstrings as a possible domain key in the type system
- \[Module] Preserve file metadata from each clause in type system warnings
- \[Module] Fix type warnings for protocol implementations whose protocol module defines additional callbacks
- \[Module] Raise clearer type checking errors when an expected struct is removed or redefined during compilation

##### Mix

- \[mix compile] Avoid unnecessary umbrella recompilation when a path dependency's manifest is newer but unchanged
- \[mix deps.compile] Recompile fetched dependencies when their compile-time environment changes

</details>

<details>
<summary>erlang/otp (erlang)</summary>

### [`v29.0.3`](https://github.com/erlang/otp/releases/tag/OTP-29.0.3): OTP 29.0.3

[Compare Source](erlang/otp@OTP-29.0.2...OTP-29.0.3)

```
Patch Package:           OTP 29.0.3
Git Tag:                 OTP-29.0.3
Date:                    2026-07-02
Trouble Report Id:       OTP-20173, OTP-20183, OTP-20185, OTP-20186,
                         OTP-20190, OTP-20191, OTP-20194, OTP-20196,
                         OTP-20197, OTP-20198, OTP-20199, OTP-20200,
                         OTP-20201, OTP-20206, OTP-20207, OTP-20208,
                         OTP-20215, OTP-20216, OTP-20217, OTP-20220,
                         OTP-20222, OTP-20226, OTP-20227, OTP-20230,
                         OTP-20231, OTP-20232, OTP-20233
Seq num:                 CVE-2026-53422, CVE-2026-54886,
                         CVE-2026-54887, CVE-2026-54891,
                         CVE-2026-55950, CVE-2026-55952, ERIERL-1333,
                         GH-SA-7wp4-pc27-2vj9, GH-SA-h9pw-h5w4-h976,
                         PR-11209, PR-11215, PR-11219, PR-11230,
                         PR-11239, PR-11244, PR-11247, PR-11250,
                         PR-11259, PR-11268, PR-11269, PR-11270,
                         PR-11271, PR-11281, PR-11282, PR-11283,
                         PR-11289, PR-11294, PR-11295, PR-11299,
                         PR-11302, PR-11306, PR-11307, PR-11309,
                         PR-11311
System:                  OTP
Release:                 29
Application:             common_test-1.31.1, compiler-10.0.2,
                         crypto-5.9.1, dialyzer-6.0.2, erts-17.0.3,
                         kernel-11.0.3, public_key-1.21.3, ssh-6.0.2,
                         ssl-11.7.3, stdlib-8.0.2
Predecessor:             OTP 29.0.2
```

Check out the git tag OTP-29.0.3, and build a full OTP system including documentation. Apply one or more applications from this build as patches to your installation using the 'otp\_patch\_apply' tool. For information on install requirements, see descriptions for each application version below.

### common\_test-1.31.1

The common\_test-1.31.1 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Fixed a crash in ct\_netconfc that occurred when the remote server closed the SSH connection during NETCONF subsystem negotiation.

  Own Id: OTP-20191\
  Related Id(s): ERIERL-1333, [PR-11230]

> #### Full runtime dependencies of common\_test-1.31.1
>
> compiler-10.0, crypto-4.5, debugger-4.1, erts-7.0, ftp-1.0, inets-6.0, kernel-11.0, observer-2.1, runtime\_tools-1.8.16, sasl-2.5, snmp-5.1.2, ssh-4.0, stdlib-8.0, syntax\_tools-1.7, tools-3.2, xmerl-1.3.8

### compiler-10.0.2

The compiler-10.0.2 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Several compiler bugs that could crash the compiler or generate incorrect code in rare circumstances have been fixed.

  Own Id: OTP-20222\
  Related Id(s): [PR-11219]

> #### Full runtime dependencies of compiler-10.0.2
>
> crypto-5.1, erts-13.0, kernel-8.4, stdlib-8.0

### crypto-5.9.1

The crypto-5.9.1 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- `crypto:compute_key/4` for `eddh` and `crypto:generate_key/2,3` for `eddh`/`eddsa` now raise an `error:{notsup, Info, Description}` exception instead of returning the atom `notsup` when the underlying cryptolib lacks support.

  Own Id: OTP-20215\
  Related Id(s): [PR-11302]

> #### Full runtime dependencies of crypto-5.9.1
>
> erts-9.0, kernel-6.0, stdlib-3.9

### dialyzer-6.0.2

The dialyzer-6.0.2 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Fix a bug with native record sets in `erl_types.erl`

  Own Id: OTP-20201

> #### Full runtime dependencies of dialyzer-6.0.2
>
> compiler-10.0, erts-12.0, kernel-8.0, stdlib-5.0, syntax\_tools-2.0

### erts-17.0.3

The erts-17.0.3 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Fixed an undefined behavior in the internal `erts_qsort()` function, which could have been the cause of a beam crash seen when updating large maps.

  Own Id: OTP-20185\
  Related Id(s): [PR-11215]

- Calculating `bxor` of the largest supported positive integer (`erlang:system_info(max_integer)`) and `-1` would return `[]` instead of a raising a `system_limit` exception.

  Own Id: OTP-20208\
  Related Id(s): [PR-11269]

- Fix possible race between `ets:delete/1` and terminating process with a fixation on the same table.

  Own Id: OTP-20217\
  Related Id(s): [PR-11283]

- A few code generation issues for the JIT on AArch64 (ARM64) have been fixed.

  For all platforms, the loader will reject some invalid BEAM files earlier.

  Own Id: OTP-20226\
  Related Id(s): [PR-11299]

- On 32-bit computers, the `md5` BIFs would return an incorrect MD5 checksum for data of size 4GiB or more.

  Own Id: OTP-20227\
  Related Id(s): [PR-11289]

> #### Full runtime dependencies of erts-17.0.3
>
> kernel-9.0, sasl-3.3, stdlib-4.1

### kernel-11.0.3

The kernel-11.0.3 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- inet:info/1 could crash when calling for a closing (port) socket.

  Own Id: OTP-20173

- Handling of the truncation bit in `inet_res` has been fixed so it properly falls back to querying over TCP after a truncated UDP reply.

  This fixes a bug introduced in OTP-28.4.2 - kernel-10.6.2 making a truncated UDP answer fail to parse and never execute the fallback, instead the name resolve operation fails.

  Own Id: OTP-20199\
  Related Id(s): [PR-11247]

> #### Full runtime dependencies of kernel-11.0.3
>
> crypto-5.8, erts-17.0, sasl-3.0, stdlib-8.0

### public\_key-1.21.3

The public\_key-1.21.3 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Hardened OCSP response verification by using constant-time hash comparisons and rejecting responses exceeding 100 KB before ASN.1 decoding.

  Own Id: OTP-20197\
  Related Id(s): [PR-11239]

> #### Full runtime dependencies of public\_key-1.21.3
>
> asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0

### ssh-6.0.2

The ssh-6.0.2 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Fixed a path-existence oracle in the SFTP server where `SSH_FXP_REALPATH` requests with `..` components could bypass the configured root directory isolation, allowing an authenticated client to determine whether arbitrary paths exist on the host filesystem.

  Own Id: OTP-20183\
  Related Id(s): [GH-SA-h9pw-h5w4-h976], [PR-11294], [CVE-2026-53422]

- Fixed an infinite loop in the SFTP server triggered when receiving `SSH_MSG_CHANNEL_EXTENDED_DATA` on an SFTP channel, which caused the channel process to spin indefinitely on CPU without consuming its message queue.

  Own Id: OTP-20186\
  Related Id(s): [GH-SA-7wp4-pc27-2vj9], [PR-11295], [CVE-2026-54886]

- Fixed mlkem768x25519 hybrid key exchange failing intermittently with "incorrect signature" when the X25519 shared secret had a leading zero byte. The shared secret is now encoded as a fixed-width 32-byte string per the specification.

  Own Id: OTP-20196\
  Related Id(s): [PR-11209]

- Fixed a race condition where SSH keepalive responses could be matched to unrelated pending requests due to incorrect request queue ordering. Requests are now matched in the order they were sent.

  Own Id: OTP-20198\
  Related Id(s): [PR-11244]

- The SFTP server now caps the read length in `SSH_FXP_READ` requests to 255 KiB (matching OpenSSH's `SFTP_MAX_READ_LENGTH`), preventing excessive memory allocation when clients request large reads.

  Own Id: OTP-20200\
  Related Id(s): [PR-11259]

- Removed a server-side workaround (OTP-14827, introduced in OTP 20) that accepted SHA-1 user-auth signatures from clients identifying as OpenSSH 7.x when rsa-sha2-\* was negotiated. The workaround addressed a distro-specific build issue in 2017 that no longer exists. Clients affected by this removal (extremely unlikely — requires a 10-year-old unpatched OpenSSH build) will see authentication failures and must upgrade.

  Own Id: OTP-20206\
  Related Id(s): [PR-11268]

> #### Full runtime dependencies of ssh-6.0.2
>
> crypto-5.7, erts-14.0, kernel-10.3, public\_key-1.6.1, runtime\_tools-1.15.1, stdlib-8.0

### ssl-11.7.3

Note! The ssl-11.7.3 application *cannot* be applied independently of other applications on an arbitrary OTP 29 installation.

```
   On a full OTP 29 installation, also the following runtime
   dependency has to be satisfied:
   -- public_key-1.21.1 (first satisfied in OTP 29.0.1)
```

#### Fixed Bugs and Malfunctions

- Correct small behavior bugs that occasionally could cause DTLS connection errors, unwanted behavior for legacy DHE\_DSS, hiding of a distribution config error, and possible unorderly process tree shutdown.

  Own Id: OTP-20190\
  Related Id(s): [PR-11250]

- Initialize DTLS cookie to random value to avoid DoS attack with forged cookie during startup window.

  Own Id: OTP-20194\
  Related Id(s): [PR-11271], [CVE-2026-54887]

- Guard TLS client for MITM injection of application data during "plain-text-window" during handshake.

  Own Id: OTP-20207\
  Related Id(s): [PR-11270], [CVE-2026-54891]

- Improve error handling of TLS PSK sending ILLIGAL\_PARMETER alert if binders and PSK-identities are not matched. Also mend recovery mechanism of ticket and session stores to be as resilient as possible to intermediate bugs.

  Own Id: OTP-20216\
  Related Id(s): [PR-11282], [CVE-2026-55952]

- Fix race condition that could be used to DoS attack DTLS servers.

  Own Id: OTP-20220\
  Related Id(s): [PR-11306], [CVE-2026-55950]

- A TLS-1.3 stateless session ticket with obfuscated\_ticket\_age set to zero was incorrectly accepted without checking the server-side ticket lifetime or the RFC 8446 Section 8.3 freshness window. The server now always validates ticket age using its own timestamp regardless of the client-reported age value.

  Own Id: OTP-20230\
  Related Id(s): [PR-11307]

- TLS-1.3 client rejects a second HelloRetryRequest as requiered in RFC 8446 Section 4.1.4

  Own Id: OTP-20231\
  Related Id(s): [PR-11309]

- A busy client node could self-trigger a ticket store crash if unlucky with scheduling if auto mode is used.

  Own Id: OTP-20232\
  Related Id(s): [PR-11311]

- Correct spec for CRL API

  Own Id: OTP-20233\
  Related Id(s): [PR-11281]

> #### Full runtime dependencies of ssl-11.7.3
>
> crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public\_key-1.21.1, runtime\_tools-1.15.1, stdlib-7.0

### stdlib-8.0.2

The stdlib-8.0.2 application can be applied independently of other applications on a full OTP 29 installation.

#### Fixed Bugs and Malfunctions

- Several compiler bugs that could crash the compiler or generate incorrect code in rare circumstances have been fixed.

  Own Id: OTP-20222\
  Related Id(s): [PR-11219]

> #### Full runtime dependencies of stdlib-8.0.2
>
> compiler-5.0, crypto-4.5, erts-16.0.3, kernel-11.0, sasl-3.0, syntax\_tools-3.2.1

### Thanks to

Cole Christensen, Nick Krichevsky, Stefan Grundmann

[cve-2026-53422]: https://nvd.nist.gov/vuln/detail/CVE-2026-53422

[cve-2026-54886]: https://nvd.nist.gov/vuln/detail/CVE-2026-54886

[cve-2026-54887]: https://nvd.nist.gov/vuln/detail/CVE-2026-54887

[cve-2026-54891]: https://nvd.nist.gov/vuln/detail/CVE-2026-54891

[cve-2026-55950]: https://nvd.nist.gov/vuln/detail/CVE-2026-55950

[cve-2026-55952]: https://nvd.nist.gov/vuln/detail/CVE-2026-55952

[gh-sa-7wp4-pc27-2vj9]: https://github.com/erlang/otp/issues/SA-7wp4-pc27-2vj9

[gh-sa-h9pw-h5w4-h976]: https://github.com/erlang/otp/issues/SA-h9pw-h5w4-h976

[pr-11209]: erlang/otp#11209

[pr-11215]: erlang/otp#11215

[pr-11219]: erlang/otp#11219

[pr-11230]: erlang/otp#11230

[pr-11239]: erlang/otp#11239

[pr-11244]: erlang/otp#11244

[pr-11247]: erlang/otp#11247

[pr-11250]: erlang/otp#11250

[pr-11259]: erlang/otp#11259

[pr-11268]: erlang/otp#11268

[pr-11269]: erlang/otp#11269

[pr-11270]: erlang/otp#11270

[pr-11271]: erlang/otp#11271

[pr-11281]: erlang/otp#11281

[pr-11282]: erlang/otp#11282

[pr-11283]: erlang/otp#11283

[pr-11289]: erlang/otp#11289

[pr-11294]: erlang/otp#11294

[pr-11295]: erlang/otp#11295

[pr-11299]: erlang/otp#11299

[pr-11302]: erlang/otp#11302

[pr-11306]: erlang/otp#11306

[pr-11307]: erlang/otp#11307

[pr-11309]: erlang/otp#11309

[pr-11311]: erlang/otp#11311

</details>

<details>
<summary>goreleaser/nfpm (goreleaser/nfpm)</summary>

### [`v2.47.0`](https://github.com/goreleaser/nfpm/releases/tag/v2.47.0)

[Compare Source](goreleaser/nfpm@v2.46.3...v2.47.0)

##### Changelog

##### New Features

- [`5c2f7ca`](goreleaser/nfpm@5c2f7ca): feat: RiscV64 support ([#&#8203;1091](goreleaser/nfpm#1091)) ([@&#8203;ahqsoftwares](https://github.com/ahqsoftwares))
- [`64b788a`](goreleaser/nfpm@64b788a): feat: add Requires(Post) for RPMS ([#&#8203;1085](goreleaser/nfpm#1085)) ([@&#8203;teddelin](https://github.com/teddelin))
- [`dc96073`](goreleaser/nfpm@dc96073): feat: add fang support for styled CLI output ([#&#8203;1068](goreleaser/nfpm#1068)) ([@&#8203;caarlos0](https://github.com/caarlos0))

##### Security updates

- [`060af04`](goreleaser/nfpm@060af04): sec(deps): update golang.org/x/crypto ([@&#8203;caarlos0](https://github.com/caarlos0))
- [`f769631`](goreleaser/nfpm@f769631): sec(deps): update golang.org/x/net ([@&#8203;caarlos0](https://github.com/caarlos0))

##### Bug fixes

- [`3118ec1`](goreleaser/nfpm@3118ec1): fix: tolerate empty overrides packager clause ([#&#8203;1080](goreleaser/nfpm#1080)) ([@&#8203;dleske](https://github.com/dleske))

##### Dependency updates

- [`a2d9ce5`](goreleaser/nfpm@a2d9ce5): feat(deps): go1.26.4 ([@&#8203;caarlos0](https://github.com/caarlos0))
- [`9b16218`](goreleaser/nfpm@9b16218): fix(deps): bump alpine from 3.23.3 to 3.23.4 ([#&#8203;1075](goreleaser/nfpm#1075)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot])
- [`e3102b3`](goreleaser/nfpm@e3102b3): fix(deps): bump alpine from 3.23.3 to 3.23.4 in /testdata/acceptance ([#&#8203;1076](goreleaser/nfpm#1076)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot])
- [`62c555e`](goreleaser/nfpm@62c555e): fix(deps): bump alpine from 3.23.4 to 3.24.0 ([#&#8203;1098](goreleaser/nfpm#1098)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot])
- [`071ae18`](goreleaser/nfpm@071ae18): fix(deps): bump alpine from 3.23.4 to 3.24.0 in /testdata/acceptance ([#&#8203;1099](goreleaser/nfpm#1099)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot])

##### Build process updates

- [`4c62d34`](goreleaser/nfpm@4c62d34): ci(deps): bump github/codeql-action in the actions group ([#&#8203;1083](goreleaser/nfpm#1083)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot])
- [`38a05de`](goreleaser/nfpm@38a05de): ci(deps): bump the actions group across 1 directory with 3 updates ([#&#8203;1096](goreleaser/nfpm#1096)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot])
- [`6fe4da4`](goreleaser/nfpm@6fe4da4): ci(deps): bump the actions group across 1 directory with 7 updates ([#&#8203;1095](goreleaser/nfpm#1095)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot])
- [`cd95f9f`](goreleaser/nfpm@cd95f9f): ci(deps): bump the actions group with 2 updates ([#&#8203;1078](goreleaser/nfpm#1078)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot])
- [`8f9cbef`](goreleaser/nfpm@8f9cbef): ci(deps): bump the actions group with 3 updates ([#&#8203;1090](goreleaser/nfpm#1090)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot])
- [`9ff0e2f`](goreleaser/nfpm@9ff0e2f): ci(deps): bump the actions group with 4 updates ([#&#8203;1086](goreleaser/nfpm#1086)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot])
- [`2ce1832`](goreleaser/nfpm@2ce1832): ci(deps): bump the actions group with 5 updates ([#&#8203;1074](goreleaser/nfpm#1074)) ([@&#8203;dependabot](https://github.com/dependabot)\[bot])
- [`1bd2fed`](goreleaser/nfpm@1bd2fed): ci: fix docs build test ([@&#8203;caarlos0](https://github.com/caarlos0))
- [`4695cdc`](goreleaser/nfpm@4695cdc): ci: fix license check ([@&#8203;caarlos0](https://github.com/caarlos0))
- [`a40b461`](goreleaser/nfpm@a40b461): ci: update build ([@&#8203;caarlos0](https://github.com/caarlos0))

##### Other work

- [`d16d75f`](goreleaser/nfpm@d16d75f): docs(deps): update hextra ([@&#8203;caarlos0](https://github.com/caarlos0))
- [`c6a6a27`](goreleaser/nfpm@c6a6a27): docs: update cmd docs ([@&#8203;caarlos0](https://github.com/caarlos0))

**Full Changelog**: <goreleaser/nfpm@v2.46.3...v2.47.0>

##### Helping out

This release is only possible thanks to **all** the support of **awesome people**!

Want to be one of them?
You can [sponsor](https://goreleaser.com/sponsors/) or [contribute with code](https://goreleaser.com/contributing).

##### Where to go next?

- nFPM is a satellite project from GoReleaser. [Check it out](https://goreleaser.com)!
- Find examples and commented usage of all options in our [website](https://nfpm.goreleaser.com/).
- Reach out on [Discord](https://discord.gg/RGEBtg8vQ6) and [Twitter](https://twitter.com/goreleaser)!

<a href="https://goreleaser.com"><img src="https://raw.githubusercontent.com/goreleaser/artwork/master/opencollective-header.png" with="100%" alt="GoReleaser logo"></a>

</details>

<details>
<summary>rabbitmq/ra (ra)</summary>

### [`v3.1.9`](https://github.com/rabbitmq/ra/releases/tag/v3.1.9)

[Compare Source](rabbitmq/ra@v3.1.8...v3.1.9)

#### What's Changed

- ci: temporary fix for windows-latest changed by [@&#8203;lshir](https://github.com/lshir) in [#&#8203;639](rabbitmq/ra#639)
- Forward follower's append\_entries\_reply when it already has the snapshot by [@&#8203;kjnilsson](https://github.com/kjnilsson) in [#&#8203;641](rabbitmq/ra#641)
- Fix stale `last_written`/`pending` state after log truncation, and a snapshot-send regression by [@&#8203;kjnilsson](https://github.com/kjnilsson) in [#&#8203;644](rabbitmq/ra#644)
- Fix `force_shrink_members_to_current_member/1` typespec by [@&#8203;visciang](https://github.com/visciang) in [#&#8203;640](rabbitmq/ra#640)

**Full Changelog**: <rabbitmq/ra@v3.1.8...v3.1.9>

</details>

<details>
<summary>wojtekmach/req (req)</summary>

### [`v0.6.3`](https://github.com/wojtekmach/req/blob/HEAD/CHANGELOG.md#v063-2026-07-16)

[Compare Source](wojtekmach/req@v0.6.2...v0.6.3)

- \[`Req.Test`]: Fix race condition

</details>

<details>
<summary>rust-lang/rust (rust)</summary>

### [`v1.97.1`](https://github.com/rust-lang/rust/blob/HEAD/RELEASES.md#Version-1971-2026-07-16)

[Compare Source](rust-lang/rust@1.97.0...1.97.1)

\==========================

<a id="1.97.1"></a>

- [rustc: Fix miscompilation in LLVM optimization](rust-lang/rust#159035)
  This backports an LLVM submodule bump to include the LLVM-side fix and a
  revert of the rustc change that is one known trigger for the bug. The rustc
  side revert should not be strictly necessary but is done out of abundance of caution.

### [`v1.97.0`](https://github.com/rust-lang/rust/blob/HEAD/RELEASES.md#Version-1970-2026-07-09)

[Compare Source](rust-lang/rust@1.96.1...1.97.0)

\==========================

<a id="1.97.0-Language"></a>

## Language

- [Consider `Result<T, Uninhabited>` and `ControlFlow<Uninhabited, T>` to be equivalent to `T` for must use lint](rust-lang/rust#148214)
- [Add allow-by-default `dead_code_pub_in_binary` lint for unused pub items in binary crates](rust-lang/rust#149509)
- [Stabilize the `div32`, `lam-bh`, `lamcas`, `ld-seq-sa` and `scq` target features](rust-lang/rust#154510)
- [Stabilize `cfg(target_has_atomic_primitive_alignment)`](rust-lang/rust#155006)
- [Allow trailing `self` in imports in more cases](rust-lang/rust#155137)

<a id="1.97.0-Platform-Support"></a>

## Platform Support

- [nvptx64-nvidia-cuda: drop support for old architectures and old ISAs](rust-lang/rust#152443)

Refer to Rust's [platform support page][platform-support-doc]
for more information on Rust's tiered platform support.

[platform-support-doc]: https://doc.rust-lang.org/rustc/platform-support.html

<a id="1.97.0-Stabilized-APIs"></a>

## Stabilized APIs

- [`Default for RepeatN`](https://doc.rust-lang.org/stable/std/iter/struct.RepeatN.html#impl-Default-for-RepeatN%3CA%3E)
- [`Copy for ffi::FromBytesUntilNulError`](https://doc.rust-lang.org/stable/std/ffi/struct.FromBytesUntilNulError.html#impl-Copy-for-FromBytesUntilNulError)
- [`Send for std::fs::File` on UEFI](rust-lang/rust#154003)
- [`<{integer}>::isolate_highest_one`](https://doc.rust-lang.org/stable/std/primitive.u32.html#method.isolate_highest_one)
- [`<{integer}>::isolate_lowest_one`](https://doc.rust-lang.org/stable/std/primitive.u32.html#method.isolate_lowest_one)
- [`<{integer}>::highest_one`](https://doc.rust-lang.org/stable/std/primitive.u32.html#method.highest_one)
- [`<{integer}>::lowest_one`](https://doc.rust-lang.org/stable/std/primitive.u32.html#method.lowest_one)
- [`<{integer}>::bit_width`](https://doc.rust-lang.org/stable/std/primitive.u32.html#method.bit_width)
- [`NonZero<{integer}>::isolate_highest_one`](https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.isolate_highest_one)
- [`NonZero<{integer}>::isolate_lowest_one`](https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.isolate_lowest_one)
- [`NonZero<{integer}>::highest_one`](https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.highest_one)
- [`NonZero<{integer}>::lowest_one`](https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.lowest_one)
- [`NonZero<{integer}>::bit_width`](https://doc.rust-lang.org/stable/std/num/struct.NonZero.html#method.bit_width)

These previously stable APIs are now stable in const contexts:

- [`char::is_control`](https://doc.rust-lang.org/stable/std/primitive.char.html#method.is_control)

<a id="1.97.0-Cargo"></a>

## Cargo

- [Stabilize `build.warnings` config.](rust-lang/cargo#16796) This controls how lint warnings from local packages are treated. Useful for enforcing a warning-free build in CI, replacing `-Dwarnings`. [docs](https://doc.rust-lang.org/nightly/cargo/reference/config.html#buildwarnings)
- [Stabilize `resolver.lockfile-path` config.](rust-lang/cargo#16694) This allows specifying the path to the lockfile to use when resolving dependencies. Useful when working with read-only source directories. [docs](https://doc.rust-lang.org/nightly/cargo/reference/config.html#resolverlockfile-path)
- [cargo-clean: Error when `--target-dir` doesn't look like a Cargo target directory.](rust-lang/cargo#16712) This prevents accidental deletion of non-target directories.
- [Add `-m` shorthand for `--manifest-path`](rust-lang/cargo#16858)
- [Remove `curl` dependency from `crates-io` crate](rust-lang/cargo#16936)

<a id="1.97.0-Rustdoc"></a>

## Rustdoc

- [Stabilize `--emit` flag](rust-lang/rust#146220)
- [Stabilize `--remap-path-prefix`](rust-lang/rust#155307)

<a id="1.97.0-Compatibility-Notes"></a>

## Compatibility Notes

- [Emit a future-compatibility warning when relying on `f32: From<{float}>` to constrain `{float}`](rust-lang/rust#139087)
- [Rust will use the v0 symbol mangling scheme by default.](rust-lang/rust#151994) This may cause some tools (such as debuggers or profilers, especially with old versions) to fail to demangle symbols emitted by Rust. It may also cause the formatting of text in backtraces to change.
- [Prevent deref coercions in `pin!`, in order to prevent unsoundness.](rust-lang/rust#153457) The most likely case where this might impact users is: writing `pin!(x)` where `x` has type `&mut T` will now always correctly produce a value of type `Pin<&mut &mut T>`, instead of sometimes allowing a coercion that produces a value of type `Pin<&mut T>`. This coercion was previously incorrectly allowed since Rust 1.88.0.
- [Deprecate `std::char` constants and functions](rust-lang/rust#153873)
- [Warn on linker output by default](rust-lang/rust#153968)
- [Remove hidden `f64` methods which have been deprecated since 1.0](rust-lang/rust#153975)
- [report the `varargs_without_pattern` lint in deps](rust-lang/rust#154599)
- [Forbid passing generic arguments to module path segments even if the module reexports a generic enum variant](rust-lang/rust#154971)
- [Error on invalid macho `link_section` specifier](rust-lang/rust#155065)
- The encoding of certain `enum`s [have changed](rust-lang/rust#155473).  This is not a breaking change, as it only applies to `enum`s without layout guarantees, but is noted here as we've seen people impacted from having made assumptions about the layout algorithm.
- [Error on `#[export_name = "..."]` where the name is empty](rust-lang/rust#155515)
- [Syntactically reject tuple index shorthands in struct patterns](rust-lang/rust#155698)
- [validate `#[link_name = "..."]` & `#[link(name = "...")]` parameters](rust-lang/rust#155817)
- On Windows, after calling `shutdown` on a socket to shut down the write side, attempting to write to the socket will now produce a `BrokenPipe` error rather than `Other`. [Map `WSAESHUTDOWN` to `io::ErrorKind::BrokenPipe`](rust-lang/rust#156063)

### [`v1.96.1`](https://github.com/rust-lang/rust/blob/HEAD/RELEASES.md#Version-1961-2026-06-30)

[Compare Source](rust-lang/rust@1.96.0...1.96.1)

\===========================

<a id="1.96.1"></a>

- [Cargo: fix timeout/retry behavior](rust-lang/cargo#17131)
- [Cargo: apply patches for CVE-2025-15661, CVE-2026-55199, and CVE-2026-55200 to libssh2](rust-lang/cargo#17140)
- [rustc: fix miscompilation in MIR optimization](rust-lang/rust#158214)

</details>

<details>
<summary>serde-rs/serde (serde)</summary>

### [`v1.0.229`](https://github.com/serde-rs/serde/releases/tag/v1.0.229)

[Compare Source](serde-rs/serde@v1.0.228...v1.0.229)

- Update to syn 3

</details>

<details>
<summary>whatyouhide/stream_data (stream_data)</summary>

### [`v1.4.0`](https://github.com/whatyouhide/stream_data/blob/HEAD/CHANGELOG.md#v140)

[Compare Source](whatyouhide/stream_data@v1.3.0...v1.4.0)

- Require Elixir 1.14+.
  - Fix `StreamData.float/1` when min and max are too far apart.
  - Support choosing between graphemes and codepoints in `StreamData.string/2`.
  - Shrink `StreamData.one_of/1` towards earlier elements first (instead of smaller values for later elements).

</details>

<details>
<summary>dtolnay/thiserror (thiserror)</summary>

### [`v2.0.19`](https://github.com/dtolnay/thiserror/releases/tag/2.0.19)

[Compare Source](dtolnay/thiserror@2.0.18...2.0.19)

- Update to syn 3

</details>

---

### Configuration

📅 **Schedule**: (in timezone Pacific/Auckland)

- Branch creation
  - Between 12:00 AM and 03:59 AM, only on Monday (`* 0-3 * * 1`)
- Automerge
  - Between 12:00 AM and 03:59 AM (`* 0-3 * * *`)

🚦 **Automerge**: Enabled.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNTUuMiIsInVwZGF0ZWRJblZlciI6IjQzLjI1NS4yIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

Co-authored-by: James Harton <james@harton.dev>
Reviewed-on: https://harton.dev/project-neon/neonfs/pulls/1568
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

team:PS Assigned to OTP team PS testing currently being tested, tag is used by OTP internal CI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants