Executive brief
A vulnerability in the Erlang/OTP SSH library could allow an authenticated user to cause excessive resource consumption on the server. By sending specially crafted SFTP file handles, an attacker can exhaust CPU and memory, potentially leading to a denial of service or system instability. This affects systems where the SFTP subsystem is enabled, which is the default configuration.
Technical details
The SFTP server implementation in Erlang/OTP (ssh_sftpd.erl) fails to enforce size limits on file handle strings provided by clients. According to SFTP specifications (draft-ietf-secsh-filexfer-02), file handles should not exceed 256 bytes; however, the vulnerable versions do not validate this length during operations such as CLOSE, FSTAT, READ, or WRITE. An authenticated attacker can provide excessively large handles to trigger uncontrolled resource allocation (CWE-770) and CPU consumption. The vulnerability is reachable over the network if the SFTP subsystem is enabled (default). Patches have been released in OTP versions 28.0.3, 27.3.4.3, and 26.2.5.15.
Affected products
- Erlang/OTP ssh 3.0.1 to 5.3.2, 5.2.11.2, 5.1.4.11
- Erlang/OTP OTP 17.0 to 28.0.2, 27.3.4.2, 26.2.5.14
Timeline
- 2025-08-27: other: Initial patch commits authored
- 2025-09-10: patched: Fixes merged into master branch and security advisory published
- 2025-09-11: disclosed: CVE published to NVD
References
- https://cna.erlef.org/cves/CVE-2025-48038.html
- https://github.com/erlang/otp/commit/4e3bf86777ab3db7220c11d8ddabf15970ddd10a
- https://github.com/erlang/otp/commit/f09e0201ff701993dc24a08f15e524daf72db42f
- https://github.com/erlang/otp/pull/10156
- https://github.com/erlang/otp/security/advisories/GHSA-pvj7-9652-7h9r
- https://www.erlang.org/doc/system/versions.html