CVE-2025-30211

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 28, 2025
CWE ID 789

Summary

CVE-2025-30211: A memory consumption vulnerability affects Erlang/OTP, a collection of libraries used in the Erlang programming language, prior to versions OTP-27.3.1, 26.2.5.10, and 25.3.2.19. Maliciously formed KEX init messages can trigger high memory usage due to insufficient checks on algorithm names. These long names may lead to inefficient processing of error data, causing excessive memory allocation. The issue is resolved in OTP-27.3.1, OTP-26.2.5.10, and OTP-25.3.2.19. Partial mitigations include setting `parallel_login` to `false` and reducing the `max_sessions` option.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share