SSH_FXP_OPENDIR may Lead to Exhaustion of File Handles
## Summary Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh\_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is associated with program files lib/ssh/src/ssh\_sftpd.erl. This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12. ## Workaround \* disabling SFTP \* limiting number of max\_sessions allowed for sshd, so exploiting becomes more complicated ## Configuration The SFTP subsystem must be enabled on the SSH server and the SSH port must be reachable by the attacker. SFTP is enabled by default unless explicitly disabled by setting {subsystems, \[\]} in the SSH daemon configuration.
02 / AFFECTED SOFTWARE
Affected packages
79 explicit affected versions
64 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl. This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12.
## Summary Allocation of Resources Without Limits or Throttling vulnerability in Erlang OTP ssh (ssh\_sftp modules) allows Excessive Allocation, Flooding. This vulnerability is associated with program files lib/ssh/src/ssh\_sftpd.erl. This issue affects OTP from OTP 17.0 before OTP 28.0.3, OTP 27.3.4.3 and OTP 26.2.5.15, corresponding to ssh from 3.0.1 before 5.3.3, 5.2.11.3 and 5.1.4.12. ## Workaround \* disabling SFTP \* limiting number of max\_sessions allowed for sshd, so exploiting becomes more complicated ## Configuration The SFTP subsystem must be enabled on the SSH server and the SSH port must be reachable by the attacker. SFTP is enabled by default unless explicitly disabled by setting {subsystems, \[\]} in the SSH daemon configuration.
05 / REFERENCES
Further evidence
- https://cna.erlef.org/cves/CVE-2025-48041.html
- https://github.com
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/48xxx/CVE-2025-48041.json
- https://github.com/erlang/otp
- https://github.com/erlang/otp/commit/5f9af63eec4657a37663828d206517828cb9f288
- https://github.com/erlang/otp/commit/d49efa2d4fa9e6f7ee658719cd76ffe7a33c2401
- https://github.com/erlang/otp/pull/10157
- https://github.com/erlang/otp/security/advisories/GHSA-79c4-cvv7-4qm3
- https://nvd.nist.gov/vuln/detail/CVE-2025-48041
- https://osv.dev/vulnerability/EEF-CVE-2025-48041
- https://www.erlang.org/doc/system/versions.html#order-of-versions