| Patch Package | OTP 28.5.0.7 |
| Git Tag | OTP-28.5.0.7 |
| Date | 2026-09-22 |
| Version Tree | Which releases contain 28.5.0.7 |
| Issue Id | |
| System | OTP |
| Release | 28 |
| Application | |
| Potential Incompatibilities |
Potential Incompatibilities #
- OTP-20118
-
- Application(s):
- stdlib
- Related Id(s):
-
ERIERL-1361, PR-11167
When
beam_libreturns an error tuple, the filename in the information tuple is now a list of characters instead of an atom.Example:
1> beam_lib:chunks(code:which(lists), ["nope"]). {error,beam_lib, {missing_chunk,".../git/otp/lib/stdlib/ebin/lists.beam", "nope"}}The reason for this change is that a long file name is not guaranteed to fit in an atom. Applications or tools that do deep inspection of the
beam_liberrors (not recommended) will need to be updated. - OTP-20287
-
- Application(s):
- ssh
- Related Id(s):
Fixed a vulnerability where the
max_channelsdaemon option was not enforced for session channels without an active subsystem, allowing a remote authenticated user to open an infinite number of channels and exhaust server resources despite the configured limit.The default value of the max_channels daemon option has been changed from infinity to 256. Deployments requiring more than 256 simultaneous channels per connection can restore the previous behavior by setting
{max_channels, infinity}.The default value of the max_sessions daemon option has been changed from infinity to 1024. Deployments requiring more concurrent SSH connections can restore the previous behavior by setting
{max_sessions, infinity}.
asn1-5.4.3.1 #
The asn1-5.4.3.1 application can be applied independently of other applications on a full OTP 28 installation.
- OTP-20272
-
- Related Id(s):
Fixed a denial-of-service attack in asn1, where abnormally large OID components (arcs) could cause resource exhaustion.
- OTP-20355
-
- Related Id(s):
-
ERIERL-1355, PR-11559
The JER backend will no longer break certain values (true, false, null) when they are typed as ENUMERATED, they will now be encoded as strings as required by the standard.
Full runtime dependencies of asn1-5.4.3.1
erts-14.0, kernel-9.0, stdlib-5.0
compiler-9.0.6.3 #
The compiler-9.0.6.3 application can be applied independently of other applications on a full OTP 28 installation.
- OTP-20365
-
In rare circumstances, the type analysis pass of the compiler could run for many minutes.
- OTP-20386
-
Certain uses of funs could crash the compiler. For example:
f() -> F = fun Fn(0) -> 0; Fn(N) -> Fn(N - 1) end, [F(X) || X <- [1, 2]].This has been corrected.
Full runtime dependencies of compiler-9.0.6.3
crypto-5.1, erts-13.0, kernel-8.4, stdlib-6.0
mnesia-4.25.3.3 #
The mnesia-4.25.3.3 application can be applied independently of other applications on a full OTP 28 installation.
- OTP-20256
-
Fixed
mnesia:force_load_table/1getting stuck when the remote node becomes unreachable during table loading. When a network loader is aborted due to sender node going down and a user has forced a table load, we now retry loading from disc instead. Additionally, for disc_only_copies tables, the process actually loading the table is the dets server process, not the mnesia loader, so it would not receive the abort notification and would hang indefinitely. Now it correctly receives the notification and aborts table loading.
Full runtime dependencies of mnesia-4.25.3.3
erts-9.0, kernel-5.3, stdlib-5.0
public_key-1.20.3.5 #
Note! The public_key-1.20.3.5 application cannot be applied independently of other applications on an arbitrary OTP 28 installation.
On a full OTP 28 installation, also the following runtime
dependency has to be satisfied:
-- crypto-5.8 (first satisfied in OTP 28.3)
- OTP-20393
-
- Related Id(s):
Handle that policy qualifiers are optional.
Full runtime dependencies of public_key-1.20.3.5
asn1-5.0, crypto-5.8, erts-13.0, kernel-8.0, stdlib-4.0
ssh-5.5.2.6 #
Note! The ssh-5.5.2.6 application cannot be applied independently of other applications on an arbitrary OTP 28 installation.
On a full OTP 28 installation, also the following runtime
dependency has to be satisfied:
-- crypto-5.7 (first satisfied in OTP 28.1)
- OTP-20287
-
- POTENTIAL INCOMPATIBILITY
Fixed a vulnerability where the
max_channelsdaemon option was not enforced for session channels without an active subsystem, allowing a remote authenticated user to open an infinite number of channels and exhaust server resources despite the configured limit.The default value of the max_channels daemon option has been changed from infinity to 256. Deployments requiring more than 256 simultaneous channels per connection can restore the previous behavior by setting
{max_channels, infinity}.The default value of the max_sessions daemon option has been changed from infinity to 1024. Deployments requiring more concurrent SSH connections can restore the previous behavior by setting
{max_sessions, infinity}. - OTP-20371
-
The SSH daemon no longer rejects a
subsystemrequest that is preceded byenvorpty-reqrequest on the same channel.
Full runtime dependencies of ssh-5.5.2.6
crypto-5.7, erts-14.0, kernel-10.3, public_key-1.6.1, runtime_tools-1.15.1, stdlib-5.0, stdlib-6.0
ssl-11.6.0.6 #
Note! The ssl-11.6.0.6 application cannot be applied independently of other applications on an arbitrary OTP 28 installation.
On a full OTP 28 installation, also the following runtime
dependencies have to be satisfied:
-- crypto-5.8 (first satisfied in OTP 28.3)
-- public_key-1.20.3.1 (first satisfied in OTP 28.5.0.1)
- OTP-20327
-
Undecodable
certificate_authoritiesnames are now skipped, as they are just a hint. - OTP-20358
-
- Related Id(s):
-
ERIERL-1356, PR-11570
Corrected generated keylog information generated from the
keylog_hsoption in the corner case that it was invoked after the client had reached its connection state, but the server closed the connection before it reached its connection state. - OTP-20388
-
- Related Id(s):
Reject unsolicited TLS-1.3 pre_shared_key in client.
- OTP-20390
-
- Related Id(s):
Security and robustness hardening returning RFC mandated alert reasons, narrowing/correcting length checks.
Correct signature algorithm handling that slightly mixed up signature algorithms and signature algorithms cert in TLS-1.2.
Add missing TLS-1.3 Brainpool groups support. (Not relevant in 27 patch)
Enhanced/corrected documentation and spec errors/deviations.
Full runtime dependencies of ssl-11.6.0.6
crypto-5.8, erts-16.0, inets-5.10.7, kernel-10.3, public_key-1.20.3.1, runtime_tools-1.15.1, stdlib-7.0
stdlib-7.3.0.3 #
Note! The stdlib-7.3.0.3 application cannot be applied independently of other applications on an arbitrary OTP 28 installation.
On a full OTP 28 installation, also the following runtime
dependency has to be satisfied:
-- erts-16.0.3 (first satisfied in OTP 28.0.3)
- OTP-20118
-
- POTENTIAL INCOMPATIBILITY
When
beam_libreturns an error tuple, the filename in the information tuple is now a list of characters instead of an atom.Example:
1> beam_lib:chunks(code:which(lists), ["nope"]). {error,beam_lib, {missing_chunk,".../git/otp/lib/stdlib/ebin/lists.beam", "nope"}}The reason for this change is that a long file name is not guaranteed to fit in an atom. Applications or tools that do deep inspection of the
beam_liberrors (not recommended) will need to be updated.
Full runtime dependencies of stdlib-7.3.0.3
compiler-5.0, crypto-4.5, erts-16.0.3, kernel-10.0, sasl-3.0, syntax_tools-3.2.1
Thanks To #
Alan Duffield, ausimian