USN-7425-1: Erlang vulnerability
Published Apr 8, 2025
·Updated
It was discovered that Erlang OTP's SSH module did not limit the size of certain data in initialization messages. An attacker could possibly use this issue to consume large amount of memory leading to a denial of service.
Affected Software
16 affected componentsFixes available
All of the following
ubuntu/erlang<1:25.3.2.12+dfsg-1ubuntu2.2
1:25.3.2.12+dfsg-1ubuntu2.2
Ubuntu Ubuntu=24.10
All of the following
ubuntu/erlang-ssh<1:25.3.2.12+dfsg-1ubuntu2.2
1:25.3.2.12+dfsg-1ubuntu2.2
Ubuntu Ubuntu=24.10
All of the following
ubuntu/erlang<1:25.3.2.8+dfsg-1ubuntu4.2
1:25.3.2.8+dfsg-1ubuntu4.2
Ubuntu Ubuntu=24.04
All of the following
ubuntu/erlang-ssh<1:25.3.2.8+dfsg-1ubuntu4.2
1:25.3.2.8+dfsg-1ubuntu4.2
Ubuntu Ubuntu=24.04
All of the following
ubuntu/erlang<1:24.2.1+dfsg-1ubuntu0.3
1:24.2.1+dfsg-1ubuntu0.3
Ubuntu Ubuntu=22.04
All of the following
ubuntu/erlang-ssh<1:24.2.1+dfsg-1ubuntu0.3
1:24.2.1+dfsg-1ubuntu0.3
Ubuntu Ubuntu=22.04
All of the following
ubuntu/erlang<1:22.2.7+dfsg-1ubuntu0.4
1:22.2.7+dfsg-1ubuntu0.4
Ubuntu Ubuntu=20.04
All of the following
ubuntu/erlang-ssh<1:22.2.7+dfsg-1ubuntu0.4
1:22.2.7+dfsg-1ubuntu0.4
Ubuntu Ubuntu=20.04
Event History
Apr 8, 2025
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7425-1?
The severity of USN-7425-1 is high due to the potential for denial of service attacks caused by memory consumption.
2
How do I fix USN-7425-1?
To fix USN-7425-1, upgrade the affected packages to the latest versions specified in the advisory.
3
What software is affected by USN-7425-1?
USN-7425-1 affects the Erlang and Erlang SSH packages on specific Ubuntu versions.
4
What versions of Ubuntu are impacted by USN-7425-1?
USN-7425-1 impacts Ubuntu versions 24.10, 24.04, 22.04, and 20.04.
5
Can USN-7425-1 lead to an exploit?
Yes, USN-7425-1 could potentially be exploited to deny service by consuming excessive memory.