Skip to content
VulniPulse
Advisory severityHigh7.5Red Hat Linux

High [CVE-2026-70399] Denial of Service via unenforced connection limit

This high-severity Red Hat Linux advisory covers CVE-2026-70399 affecting Red Hat Hardened Images.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-70399 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxUnclassified
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening and holding open a large number of connections.

The max_clients option is documented to default to 150, and the inets hardening guide presents that limit as the first layer of denial-of-service defence, but a server that does not set it explicitly accepts an unlimited number of simultaneous connections. Establishing the connections is sufficient; no valid request and no authentication are required.

The accept gate in httpd_manager:handle_new_connection/4 reads the option with httpd_util:lookup/2, which returns undefined when the key is absent, rather than the three-argument form carrying the 150 default that the neighbouring get_ustate/2 uses.

Erlang term ordering places every integer before every atom, so the Count =< Max guard holds for any connection count and the server never returns {reject, busy}. Each accepted connection occupies a worker process and a socket for as long as it is held, driving the node towards process, memory and file descriptor exhaustion.

Servers that set max_clients explicitly are unaffected, because a configured value is applied as intended.

Affected product named by the advisory: Red Hat Hardened Images.

Affected versions
  • < 17.0
  • < 27.3.4.17
  • < 28.0
  • < 28.5.0.6
  • < 29.0
  • < 29.0.6
  • < 5.10
  • < 9.3.2.7
  • < 9.4
  • < 9.6.2.3
  • < 9.7
  • < 9.7.2

Official advisory · high-confidence parse· fetched 17 days ago·verify at source

Fixed versions
  • erlang27-main-27.3.4.17-0.1.hum1
  • RHSA-2026:62531

Official advisory · high-confidence parse· fetched 17 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • To mitigate this issue, explicitly configure the `max_clients` option in the Erlang/OTP inets httpd server configuration to a reasonable value. This will enforce a limit on simultaneous connections, preventing resource exhaustion. Consult the Erlang/OTP inets documentation for specific configuration instructions. A restart or reload of the affected service may be required for the changes to take effect, which could temporarily impact service availability.

Official advisory · high-confidence parse· fetched 17 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.