Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-30211

Опубликовано: 28 мар. 2025
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.1, 26.2.5.10, and 25.3.2.19, a maliciously formed KEX init message can result with high memory usage. Implementation does not verify RFC specified limits on algorithm names (64 characters) provided in KEX init message. Big KEX init packet may lead to inefficient processing of the error data. As a result, large amount of memory will be allocated for processing malicious data. Versions OTP-27.3.1, OTP-26.2.5.10, and OTP-25.3.2.19 fix the issue. Some workarounds are available. One may set option parallel_login to false and/or reduce the max_sessions option.

РелизСтатусПримечание
devel

released

1:27.3+dfsg-1ubuntu1
esm-infra-legacy/trusty

needs-triage

esm-infra/bionic

needs-triage

esm-infra/focal

released

1:22.2.7+dfsg-1ubuntu0.4
esm-infra/xenial

needs-triage

focal

released

1:22.2.7+dfsg-1ubuntu0.4
jammy

released

1:24.2.1+dfsg-1ubuntu0.3
noble

released

1:25.3.2.8+dfsg-1ubuntu4.2
oracular

released

1:25.3.2.12+dfsg-1ubuntu2.2
plucky

released

1:27.3+dfsg-1ubuntu1

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
11 месяцев назад

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.1, 26.2.5.10, and 25.3.2.19, a maliciously formed KEX init message can result with high memory usage. Implementation does not verify RFC specified limits on algorithm names (64 characters) provided in KEX init message. Big KEX init packet may lead to inefficient processing of the error data. As a result, large amount of memory will be allocated for processing malicious data. Versions OTP-27.3.1, OTP-26.2.5.10, and OTP-25.3.2.19 fix the issue. Some workarounds are available. One may set option `parallel_login` to `false` and/or reduce the `max_sessions` option.

CVSS3: 7.5
nvd
11 месяцев назад

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.1, 26.2.5.10, and 25.3.2.19, a maliciously formed KEX init message can result with high memory usage. Implementation does not verify RFC specified limits on algorithm names (64 characters) provided in KEX init message. Big KEX init packet may lead to inefficient processing of the error data. As a result, large amount of memory will be allocated for processing malicious data. Versions OTP-27.3.1, OTP-26.2.5.10, and OTP-25.3.2.19 fix the issue. Some workarounds are available. One may set option `parallel_login` to `false` and/or reduce the `max_sessions` option.

CVSS3: 7.5
msrc
10 месяцев назад

KEX init error results with excessive memory usage

CVSS3: 7.5
debian
11 месяцев назад

Erlang/OTP is a set of libraries for the Erlang programming language. ...

CVSS3: 7.5
fstec
11 месяцев назад

Уязвимость набора библиотек OTP языка программирования Erlang, связанная с отсутсвием контроля вводимых пользователем данных, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3

Уязвимость CVE-2025-30211