High [CVE-2026-70399] Denial of Service via unenforced connection limit
This high-severity Red Hat Linux advisory covers CVE-2026-70399 affecting Red Hat Hardened Images.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Summary
Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP inets httpd allows an unauthenticated remote attacker to cause denial of service by opening and holding open a large number of connections.
The max_clients option is documented to default to 150, and the inets hardening guide presents that limit as the first layer of denial-of-service defence, but a server that does not set it explicitly accepts an unlimited number of simultaneous connections. Establishing the connections is sufficient; no valid request and no authentication are required.
The accept gate in httpd_manager:handle_new_connection/4 reads the option with httpd_util:lookup/2, which returns undefined when the key is absent, rather than the three-argument form carrying the 150 default that the neighbouring get_ustate/2 uses.
Erlang term ordering places every integer before every atom, so the Count =< Max guard holds for any connection count and the server never returns {reject, busy}. Each accepted connection occupies a worker process and a socket for as long as it is held, driving the node towards process, memory and file descriptor exhaustion.
Servers that set max_clients explicitly are unaffected, because a configured value is applied as intended.
Affected product named by the advisory: Red Hat Hardened Images.
- < 17.0
- < 27.3.4.17
- < 28.0
- < 28.5.0.6
- < 29.0
- < 29.0.6
- < 5.10
- < 9.3.2.7
- < 9.4
- < 9.6.2.3
- < 9.7
- < 9.7.2
Official advisory · high-confidence parse· fetched 17 days ago·verify at source
- erlang27-main-27.3.4.17-0.1.hum1
- RHSA-2026:62531
Official advisory · high-confidence parse· fetched 17 days ago·verify at source
Mitigation checklist
- To mitigate this issue, explicitly configure the `max_clients` option in the Erlang/OTP inets httpd server configuration to a reasonable value. This will enforce a limit on simultaneous connections, preventing resource exhaustion. Consult the Erlang/OTP inets documentation for specific configuration instructions. A restart or reload of the affected service may be required for the changes to take effect, which could temporarily impact service availability.
Official advisory · high-confidence parse· fetched 17 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.