PT-2026-96689 · Unknown+1 · Erlang/Otp+1
CVE-2026-68956
·
Published
2026-09-22
·
Updated
2026-09-22
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Erlang/OTP versions 17.0 through 27.3.4.17
Erlang/OTP versions 28.0 through 28.5.0.6
Erlang/OTP versions 29.0 through 29.1.0
ssh versions 3.0.1 through 5.2.11.12
ssh versions 5.3.0 through 5.5.2.5
ssh versions 6.0.0 through 6.0.5
Description
An authenticated remote attacker can exhaust node memory by repeatedly opening session channels that are never assigned a handler. This occurs because the
session clause of ssh connection:handle msg/4 only checks minimal remote max packet size before calling setup session/5, which unconditionally creates a #channel{} record and stores it in the ETS channel cache. Since the max channels daemon option is only checked by ssh channel sup:max num channels not exceeded/2 (which counts supervisor children), channels without a shell, exec, or subsystem handler remain invisible to this limit. Consequently, a single authenticated connection can accumulate enough channels to deplete node memory, causing the emulator to terminate and affecting all hosted applications. No credentials, file contents, or write access can be obtained through this issue.Recommendations
Update Erlang/OTP to version 27.3.4.18, 28.5.0.7, or 29.1.1.
Update ssh to version 5.2.11.13, 5.5.2.6, or 6.0.6.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Erlang/Otp
Ssh