CVE-2025-48040

EUVD-2025-27677
Uncontrolled Resource Consumption vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl.

This issue affects OTP form OTP 17.0 until OTP 28.0.3, OTP 27.3.4.3 and 26.2.5.15 corresponding to ssh from 3.0.1 until 5.3.3, 5.2.11.3 and 5.1.4.12.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 36%
Debian logo
Debian Releases
Debian Product
Codename
erlang
bookworm
1:25.2.3+dfsg-1+deb12u4
fixed
bookworm (security)
vulnerable
bullseye
postponed
bullseye (security)
vulnerable
forky
1:27.3.4.11+dfsg-1
fixed
sid
1:27.3.4.11+dfsg-7
fixed
trixie
1:27.3.4.1+dfsg-1+deb13u2
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
erlang
suse enterprise sap 15 SP7
23.3.4.19-150300.3.29.1
fixed
suse enterprise server 15 SP4
23.3.4.19-150300.3.29.1
fixed
suse enterprise server 15 SP7
23.3.4.19-150300.3.29.1
fixed
erlang-epmd
suse enterprise sap 15 SP7
23.3.4.19-150300.3.29.1
fixed
suse enterprise server 15 SP4
23.3.4.19-150300.3.29.1
fixed
suse enterprise server 15 SP7
23.3.4.19-150300.3.29.1
fixed
erlang26
suse enterprise sap 15 SP7
26.2.1-150300.7.22.1
fixed
suse enterprise server 15 SP7
26.2.1-150300.7.22.1
fixed
erlang26-epmd
suse enterprise sap 15 SP7
26.2.1-150300.7.22.1
fixed
suse enterprise server 15 SP7
26.2.1-150300.7.22.1
fixed