USN-7425-1: Erlang vulnerability
8 April 2025
Erlang could be made to consume large amount of memory.
Releases
Packages
- erlang - Concurrent, real-time, distributed functional language
Details
It was discovered that Erlang OTP's SSH module did not limit the size of
certain data in initialization messages. An attacker could possibly use
this issue to consume large amount of memory leading to a denial of
service.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.10
Ubuntu 24.04
Ubuntu 22.04
Ubuntu 20.04
In general, a standard system update will make all the necessary changes.