CVE-2025-32433

Publication date 16 April 2025

Last updated 23 April 2025


Ubuntu priority

Erlang/OTP is a set of libraries for the Erlang programming language. Prior to versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20, a SSH server may allow an attacker to perform unauthenticated remote code execution (RCE). By exploiting a flaw in SSH protocol message handling, a malicious actor could gain unauthorized access to affected systems and execute arbitrary commands without valid credentials. This issue is patched in versions OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20. A temporary workaround involves disabling the SSH server or to prevent access via firewall rules.

Why is this CVE high priority?

unauthenticated remote code execution (RCE)

Learn more about Ubuntu priority

Status

Package Ubuntu Release Status
erlang 25.04 plucky
Fixed 1:27.3+dfsg-1ubuntu1.1
24.10 oracular
Fixed 1:25.3.2.12+dfsg-1ubuntu2.3
24.04 LTS noble
Fixed 1:25.3.2.8+dfsg-1ubuntu4.3
22.04 LTS jammy
Fixed 1:24.2.1+dfsg-1ubuntu0.4
20.04 LTS focal
Fixed 1:22.2.7+dfsg-1ubuntu0.5
18.04 LTS bionic
Needs evaluation
16.04 LTS xenial
Needs evaluation
14.04 LTS trusty
Needs evaluation

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
erlang

References

Related Ubuntu Security Notices (USN)

Other references