Описание
Security update for erlang26
This update for erlang26 fixes the following issues:
- CVE-2025-48040: Excessive resource consumption (bsc#1249472)
- CVE-2025-48039: Excessive use of system resources (bsc#1249469)
- CVE-2025-48038: Excessive use of system resources (bsc#1249470)
Список пакетов
SUSE Linux Enterprise Module for Server Applications 15 SP7
openSUSE Leap 15.6
Ссылки
- Link for SUSE-SU-2026:0023-1
- E-Mail link for SUSE-SU-2026:0023-1
- SUSE Security Ratings
- SUSE Bug 1249469
- SUSE Bug 1249470
- SUSE Bug 1249472
- SUSE CVE CVE-2025-48038 page
- SUSE CVE CVE-2025-48039 page
- SUSE CVE CVE-2025-48040 page
Описание
Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP form OTP 17.0 until OTP 28.0.3, OTP 27.3.4.3 and 26.2.5.15 corresponding to ssh from 3.0.1 until 5.3.3, 5.2.11.3 and 5.1.4.12.
Затронутые продукты
Ссылки
- CVE-2025-48038
- SUSE Bug 1249470
Описание
Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Resource Leak Exposure. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP form OTP 17.0 until OTP 28.0.3, OTP 27.3.4.3 and 26.2.5.15 corresponding to ssh from 3.0.1 until 5.3.3, 5.2.11.3 and 5.1.4.12.
Затронутые продукты
Ссылки
- CVE-2025-48039
- SUSE Bug 1249469
Описание
Uncontrolled Resource Consumption vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP form OTP 17.0 until OTP 28.0.3, OTP 27.3.4.3 and 26.2.5.15 corresponding to ssh from 3.0.1 until 5.3.3, 5.2.11.3 and 5.1.4.12.
Затронутые продукты
Ссылки
- CVE-2025-48040
- SUSE Bug 1249472