USN-7656-1: Erlang vulnerabilities
USN-7656-1: Erlang vulnerabilities
Publication date : 21 July 2025
Overview: Several security issues were fixed in Erlang.
Packages
erlang - Concurrent, real-time, distributed functional language
Details
It was discovered that Erlang OTP’s SSH module incorrectly enforced strict
KEX handshake hardening measures. A remote attacker able to intercept
communications could possibly use this issue to insert optional messages
into connections during the handshake. (CVE-2025-46712)
It was discovered that Erlang OTP incorrectly handled ZIP archives. If a
user or automated system were tricked into opening a specially crafted ZIP
archive, a remote attacker could possibly use this issue to overwrite
arbitrary files outside of the intended directory. (CVE-2025-4748)
Update instructions
The problem can be corrected by updating your system to the following package versions:
25.04 plucky
- erlang – 1:27.3+dfsg-1ubuntu1.2
- erlang-ssh – 1:27.3+dfsg-1ubuntu1.2
24.04 noble - erlang – 1:25.3.2.8+dfsg-1ubuntu4.4
- erlang-ssh – 1:25.3.2.8+dfsg-1ubuntu4.4
22.04 jammy - erlang 1:24.2.1+dfsg-1ubuntu0.5
- erlang-ssh – 1:24.2.1+dfsg-1ubuntu0.5