CVE-2025-46712

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-46712
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-46712.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-46712
Aliases
  • GHSA-934x-xq38-hhqf
Published
2025-05-08T20:15:30Z
Modified
2025-05-12T18:47:27.450767Z
Summary
[none]
Details

Erlang/OTP is a set of libraries for the Erlang programming language. In versions prior to OTP-27.3.4 (for OTP-27), OTP-26.2.5.12 (for OTP-26), and OTP-25.3.2.21 (for OTP-25), Erlang/OTP SSH fails to enforce strict KEX handshake hardening measures by allowing optional messages to be exchanged. This allows a Man-in-the-Middle attacker to inject these messages in a connection during the handshake. This issue has been patched in versions OTP-27.3.4 (for OTP-27), OTP-26.2.5.12 (for OTP-26), and OTP-25.3.2.21 (for OTP-25).

References

Affected packages

Debian:11 / erlang

Package

Name
erlang
Purl
pkg:deb/debian/erlang?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:23.*

1:23.2.6+dfsg-1
1:23.2.6+dfsg-1+deb11u1
1:23.2.6+dfsg-1+deb11u2

1:24.*

1:24.0~rc1+dfsg-1
1:24.0~rc2+dfsg-1
1:24.0~rc3+dfsg-1
1:24.0.2+dfsg-1
1:24.0.3+dfsg-1
1:24.0.4+dfsg-1
1:24.0.5+dfsg-1
1:24.0.5+dfsg-2
1:24.0.6+dfsg-1
1:24.0.6+dfsg-2
1:24.1+dfsg-1
1:24.1.1+dfsg-1
1:24.1.4+dfsg-1
1:24.1.5+dfsg-1
1:24.1.7+dfsg-1
1:24.2+dfsg-1
1:24.2.1+dfsg-1
1:24.2.2+dfsg-1
1:24.3+dfsg-1
1:24.3.1+dfsg-1
1:24.3.2+dfsg-1
1:24.3.3+dfsg-1
1:24.3.4+dfsg-1
1:24.3.4.1+dfsg-1
1:24.3.4.5+dfsg-1

1:25.*

1:25.0~rc1+dfsg-1
1:25.0~rc2+dfsg-1
1:25.0~rc3+dfsg-1
1:25.0+dfsg-1
1:25.0.2+dfsg-1
1:25.0.3+dfsg-1
1:25.0.4+dfsg-1
1:25.1.1+dfsg-1
1:25.1.2+dfsg-1
1:25.2+dfsg-1
1:25.2.1+dfsg-1
1:25.2.1+dfsg-2
1:25.2.2+dfsg-1
1:25.2.3+dfsg-1
1:25.3.2.8+dfsg-1
1:25.3.2.10+dfsg-1
1:25.3.2.10+dfsg-2
1:25.3.2.11+dfsg-1
1:25.3.2.12+dfsg-1
1:25.3.2.12+dfsg-2
1:25.3.2.12+dfsg-3

1:26.*

1:26.0~rc2+dfsg-1
1:26.0~rc3+dfsg-1
1:26.0+dfsg-1
1:26.0.1+dfsg-1
1:26.0.2+dfsg-1
1:26.1.2+dfsg-1
1:26.2.1+dfsg-1
1:26.2.4+dfsg-1

1:27.*

1:27.0~rc3+dfsg-1
1:27.0~rc3+dfsg-2
1:27.0~rc3+dfsg-3
1:27.0~rc3+dfsg-4
1:27.0+dfsg-1
1:27.0.1+dfsg-1
1:27.0.1+dfsg-2
1:27.0.1+dfsg-3
1:27.1.2+dfsg-1
1:27.2+dfsg-1
1:27.2+dfsg-2
1:27.2+dfsg-3~exp1
1:27.2.1+dfsg-1
1:27.2.1+dfsg-2
1:27.2.2+dfsg-1
1:27.2.3+dfsg-1
1:27.2.4+dfsg-1
1:27.3+dfsg-1
1:27.3.1+dfsg-1
1:27.3.2+dfsg-1
1:27.3.3+dfsg-1
1:27.3.4+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / erlang

Package

Name
erlang
Purl
pkg:deb/debian/erlang?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:25.*

1:25.2.3+dfsg-1
1:25.2.3+dfsg-1+deb12u1
1:25.3.2.8+dfsg-1
1:25.3.2.10+dfsg-1
1:25.3.2.10+dfsg-2
1:25.3.2.11+dfsg-1
1:25.3.2.12+dfsg-1
1:25.3.2.12+dfsg-2
1:25.3.2.12+dfsg-3

1:26.*

1:26.0~rc2+dfsg-1
1:26.0~rc3+dfsg-1
1:26.0+dfsg-1
1:26.0.1+dfsg-1
1:26.0.2+dfsg-1
1:26.1.2+dfsg-1
1:26.2.1+dfsg-1
1:26.2.4+dfsg-1

1:27.*

1:27.0~rc3+dfsg-1
1:27.0~rc3+dfsg-2
1:27.0~rc3+dfsg-3
1:27.0~rc3+dfsg-4
1:27.0+dfsg-1
1:27.0.1+dfsg-1
1:27.0.1+dfsg-2
1:27.0.1+dfsg-3
1:27.1.2+dfsg-1
1:27.2+dfsg-1
1:27.2+dfsg-2
1:27.2+dfsg-3~exp1
1:27.2.1+dfsg-1
1:27.2.1+dfsg-2
1:27.2.2+dfsg-1
1:27.2.3+dfsg-1
1:27.2.4+dfsg-1
1:27.3+dfsg-1
1:27.3.1+dfsg-1
1:27.3.2+dfsg-1
1:27.3.3+dfsg-1
1:27.3.4+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / erlang

Package

Name
erlang
Purl
pkg:deb/debian/erlang?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1:25.*

1:25.2.3+dfsg-1
1:25.3.2.8+dfsg-1
1:25.3.2.10+dfsg-1
1:25.3.2.10+dfsg-2
1:25.3.2.11+dfsg-1
1:25.3.2.12+dfsg-1
1:25.3.2.12+dfsg-2
1:25.3.2.12+dfsg-3

1:26.*

1:26.0~rc2+dfsg-1
1:26.0~rc3+dfsg-1
1:26.0+dfsg-1
1:26.0.1+dfsg-1
1:26.0.2+dfsg-1
1:26.1.2+dfsg-1
1:26.2.1+dfsg-1
1:26.2.4+dfsg-1

1:27.*

1:27.0~rc3+dfsg-1
1:27.0~rc3+dfsg-2
1:27.0~rc3+dfsg-3
1:27.0~rc3+dfsg-4
1:27.0+dfsg-1
1:27.0.1+dfsg-1
1:27.0.1+dfsg-2
1:27.0.1+dfsg-3
1:27.1.2+dfsg-1
1:27.2+dfsg-1
1:27.2+dfsg-2
1:27.2+dfsg-3~exp1
1:27.2.1+dfsg-1
1:27.2.1+dfsg-2
1:27.2.2+dfsg-1
1:27.2.3+dfsg-1
1:27.2.4+dfsg-1
1:27.3+dfsg-1
1:27.3.1+dfsg-1
1:27.3.2+dfsg-1
1:27.3.3+dfsg-1
1:27.3.4+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}