USN-7656-1

Source
https://ubuntu.com/security/notices/USN-7656-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7656-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/USN-7656-1
Upstream
Related
Published
2025-07-21T11:51:07.348817Z
Modified
2025-07-22T20:30:58.199307Z
Summary
erlang vulnerabilities
Details

It was discovered that Erlang OTP’s SSH module incorrectly enforced strict KEX handshake hardening measures. A remote attacker able to intercept communications could possibly use this issue to insert optional messages into connections during the handshake. (CVE-2025-46712)

It was discovered that Erlang OTP incorrectly handled ZIP archives. If a user or automated system were tricked into opening a specially crafted ZIP archive, a remote attacker could possibly use this issue to overwrite arbitrary files outside of the intended directory. (CVE-2025-4748)

References

Affected packages

Ubuntu:22.04:LTS / erlang

Package

Name
erlang
Purl
pkg:deb/ubuntu/erlang@1:24.2.1+dfsg-1ubuntu0.5?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:24.2.1+dfsg-1ubuntu0.5

Affected versions

1:23.*

1:23.2.6+dfsg-1build1

1:24.*

1:24.1.1+dfsg-1
1:24.1.4+dfsg-1
1:24.1.5+dfsg-1
1:24.1.5+dfsg-1ubuntu1
1:24.2+dfsg-1
1:24.2.1+dfsg-1
1:24.2.1+dfsg-1ubuntu0.1
1:24.2.1+dfsg-1ubuntu0.2
1:24.2.1+dfsg-1ubuntu0.3
1:24.2.1+dfsg-1ubuntu0.4

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-asn1"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-asn1-dbgsym"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-base"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-base-dbgsym"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-common-test"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-common-test-dbgsym"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-crypto"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-crypto-dbgsym"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-debugger"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-dev"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-dialyzer"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-dialyzer-dbgsym"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-diameter"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-doc"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-edoc"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-eldap"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-erl-docgen"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-et"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-eunit"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-examples"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-ftp"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-inets"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-jinterface"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-manpages"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-megaco"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-megaco-dbgsym"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-mnesia"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-mode"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-nox"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-observer"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-odbc"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-odbc-dbgsym"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-os-mon"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-os-mon-dbgsym"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-parsetools"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-public-key"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-reltool"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-runtime-tools"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-runtime-tools-dbgsym"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-snmp"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-src"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-ssh"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-ssl"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-syntax-tools"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-tftp"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-tools"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-tools-dbgsym"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-wx"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-wx-dbgsym"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-x11"
        },
        {
            "binary_version": "1:24.2.1+dfsg-1ubuntu0.5",
            "binary_name": "erlang-xmerl"
        }
    ],
    "availability": "No subscription required"
}

Ubuntu:24.04:LTS / erlang

Package

Name
erlang
Purl
pkg:deb/ubuntu/erlang@1:25.3.2.8+dfsg-1ubuntu4.4?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:25.3.2.8+dfsg-1ubuntu4.4

Affected versions

1:25.*

1:25.2.3+dfsg-1
1:25.3.2.8+dfsg-1
1:25.3.2.8+dfsg-1ubuntu1
1:25.3.2.8+dfsg-1ubuntu3
1:25.3.2.8+dfsg-1ubuntu4
1:25.3.2.8+dfsg-1ubuntu4.1
1:25.3.2.8+dfsg-1ubuntu4.2
1:25.3.2.8+dfsg-1ubuntu4.3

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-asn1"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-asn1-dbgsym"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-base"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-base-dbgsym"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-common-test"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-common-test-dbgsym"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-crypto"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-crypto-dbgsym"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-debugger"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-dev"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-dialyzer"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-dialyzer-dbgsym"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-diameter"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-doc"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-edoc"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-eldap"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-erl-docgen"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-et"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-eunit"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-examples"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-ftp"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-inets"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-jinterface"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-manpages"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-megaco"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-megaco-dbgsym"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-mnesia"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-mode"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-nox"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-observer"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-odbc"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-odbc-dbgsym"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-os-mon"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-os-mon-dbgsym"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-parsetools"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-public-key"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-reltool"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-runtime-tools"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-runtime-tools-dbgsym"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-snmp"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-src"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-ssh"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-ssl"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-syntax-tools"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-tftp"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-tools"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-wx"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-wx-dbgsym"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-x11"
        },
        {
            "binary_version": "1:25.3.2.8+dfsg-1ubuntu4.4",
            "binary_name": "erlang-xmerl"
        }
    ],
    "availability": "No subscription required"
}

Ubuntu:25.04 / erlang

Package

Name
erlang
Purl
pkg:deb/ubuntu/erlang@1:27.3+dfsg-1ubuntu1.2?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1:27.3+dfsg-1ubuntu1.2

Affected versions

1:25.*

1:25.3.2.12+dfsg-1ubuntu2

1:27.*

1:27.2+dfsg-2
1:27.2.1+dfsg-1
1:27.2.1+dfsg-2
1:27.2.2+dfsg-1
1:27.2.3+dfsg-1
1:27.2.4+dfsg-1
1:27.3+dfsg-1
1:27.3+dfsg-1ubuntu1
1:27.3+dfsg-1ubuntu1.1

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-asn1"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-asn1-dbgsym"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-base"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-base-dbgsym"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-common-test"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-common-test-dbgsym"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-crypto"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-crypto-dbgsym"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-debugger"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-dev"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-dialyzer"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-dialyzer-dbgsym"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-diameter"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-doc"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-edoc"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-eldap"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-et"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-eunit"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-examples"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-ftp"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-inets"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-jinterface"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-megaco"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-megaco-dbgsym"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-mnesia"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-mode"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-nox"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-observer"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-odbc"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-odbc-dbgsym"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-os-mon"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-os-mon-dbgsym"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-parsetools"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-public-key"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-reltool"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-runtime-tools"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-runtime-tools-dbgsym"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-snmp"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-src"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-ssh"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-ssl"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-syntax-tools"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-tftp"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-tools"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-wx"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-wx-dbgsym"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-x11"
        },
        {
            "binary_version": "1:27.3+dfsg-1ubuntu1.2",
            "binary_name": "erlang-xmerl"
        }
    ],
    "availability": "No subscription required"
}