PT-2026-96689 · Unknown+1 · Erlang/Otp+1

CVE-2026-68956

·

Published

2026-09-22

·

Updated

2026-09-22

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Erlang/OTP versions 17.0 through 27.3.4.17 Erlang/OTP versions 28.0 through 28.5.0.6 Erlang/OTP versions 29.0 through 29.1.0 ssh versions 3.0.1 through 5.2.11.12 ssh versions 5.3.0 through 5.5.2.5 ssh versions 6.0.0 through 6.0.5
Description An authenticated remote attacker can exhaust node memory by repeatedly opening session channels that are never assigned a handler. This occurs because the session clause of ssh connection:handle msg/4 only checks minimal remote max packet size before calling setup session/5, which unconditionally creates a #channel{} record and stores it in the ETS channel cache. Since the max channels daemon option is only checked by ssh channel sup:max num channels not exceeded/2 (which counts supervisor children), channels without a shell, exec, or subsystem handler remain invisible to this limit. Consequently, a single authenticated connection can accumulate enough channels to deplete node memory, causing the emulator to terminate and affecting all hosted applications. No credentials, file contents, or write access can be obtained through this issue.
Recommendations Update Erlang/OTP to version 27.3.4.18, 28.5.0.7, or 29.1.1. Update ssh to version 5.2.11.13, 5.5.2.6, or 6.0.6.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-68956
GHSA-QHCM-PX9C-RVFH

Affected Products

Erlang/Otp
Ssh