OESA-2026-3651
Dashboard / Vulnerabilities / OESA-2026-3651
Summary: erlang security update
Details: Erlang is a general-purpose programming language and runtime environment. Erlang has built-in support for concurrency, distribution and fault tolerance. Erlang is used in several large telecommunication systems from Ericsson. Security Fix(es): Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP from OTP 17.0 until OTP 28.0.3, OTP 27.3.4.3 and 26.2.5.15 corresponding to ssh from 3.0.1 until 5.3.3, 5.2.11.3 and 5.1.4.12.(CVE-2025-48041)
References: https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3651, https://nvd.nist.gov/vuln/detail/CVE-2025-48041
Affected packages
Package
Name: erlang
Purl: pkg:rpm/openEuler/erlang&distro=openEuler-24.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
