Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote attacker to exhaust node memory… (CVE-2026-68956)
A resource exhaustion vulnerability exists in Erlang/OTP ssh where an authenticated remote attacker can exhaust node memory by repeatedly opening session channels that never receive a handler. This leads to accumulation of channel records in memory until the node runs out of memory and the Erlang emulator terminates, affecting all applications on the node. No file contents, credentials, or write access are exposed. The vulnerability affects OTP versions from 18.1.2 before 27.3.4.18, 28.5.0.7, and 29.1.1, corresponding to ssh versions from 4.1.1 before 5.2.11.13, 5.5.2.6, and 6.0.6. Patch status is not explicitly stated in the provided data.
AI Analysis
Technical Summary
The vulnerability (CVE-2026-68956) in Erlang/OTP ssh allows an authenticated remote attacker to exhaust node memory by repeatedly opening session channels that are never assigned a handler. The 'session' clause of ssh_connection:handle_msg/4 only checks minimal_remote_max_packet_size before calling setup_session/5, which unconditionally creates a channel record stored in the ETS channel cache. The max_channels daemon option only limits supervisor children and does not account for channels without handlers, making the limit ineffective against this attack. According to RFC 4254 section 5.1, many session channels per connection are permitted, and each channel record consumes a few hundred bytes. Consequently, a single authenticated connection can accumulate many channels, exhausting memory and causing the Erlang emulator to terminate, impacting all applications running on the node. No sensitive data or write access is compromised. The affected OTP versions are from 18.1.2 up to but not including 27.3.4.18, 28.5.0.7, and 29.1.1, with corresponding ssh versions from 4.1.1 up to but not including 5.2.11.13, 5.5.2.6, and 6.0.6. Whether versions before 18.1.2 are affected is unknown. No vendor advisory or patch information is provided in the input.
Potential Impact
An authenticated remote attacker can cause denial of service by exhausting the node's memory through repeated opening of unhandled session channels. This results in termination of the Erlang emulator, affecting all applications running on the node. There is no exposure of file contents, credentials, or write access.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vulnerability requires authentication and exploits a resource exhaustion condition, monitor for unusual SSH session channel activity and consider limiting authenticated user access until a fix is applied.
Allocation of Resources Without Limits or Throttling vulnerability in Erlang/OTP ssh allows an authenticated remote attacker to exhaust node memory… (CVE-2026-68956)
Description
A resource exhaustion vulnerability exists in Erlang/OTP ssh where an authenticated remote attacker can exhaust node memory by repeatedly opening session channels that never receive a handler. This leads to accumulation of channel records in memory until the node runs out of memory and the Erlang emulator terminates, affecting all applications on the node. No file contents, credentials, or write access are exposed. The vulnerability affects OTP versions from 18.1.2 before 27.3.4.18, 28.5.0.7, and 29.1.1, corresponding to ssh versions from 4.1.1 before 5.2.11.13, 5.5.2.6, and 6.0.6. Patch status is not explicitly stated in the provided data.
CVSS v4.0
Affected software
pkg:deb/ubuntu/erlang?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/erlang?arch=source&distro=esm-infra/xenialpkg:deb/ubuntu/erlang?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/erlang?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/erlang?arch=source&distro=jammypkg:deb/ubuntu/erlang?arch=source&distro=noblepkg:deb/ubuntu/erlang?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability (CVE-2026-68956) in Erlang/OTP ssh allows an authenticated remote attacker to exhaust node memory by repeatedly opening session channels that are never assigned a handler. The 'session' clause of ssh_connection:handle_msg/4 only checks minimal_remote_max_packet_size before calling setup_session/5, which unconditionally creates a channel record stored in the ETS channel cache. The max_channels daemon option only limits supervisor children and does not account for channels without handlers, making the limit ineffective against this attack. According to RFC 4254 section 5.1, many session channels per connection are permitted, and each channel record consumes a few hundred bytes. Consequently, a single authenticated connection can accumulate many channels, exhausting memory and causing the Erlang emulator to terminate, impacting all applications running on the node. No sensitive data or write access is compromised. The affected OTP versions are from 18.1.2 up to but not including 27.3.4.18, 28.5.0.7, and 29.1.1, with corresponding ssh versions from 4.1.1 up to but not including 5.2.11.13, 5.5.2.6, and 6.0.6. Whether versions before 18.1.2 are affected is unknown. No vendor advisory or patch information is provided in the input.
Potential Impact
An authenticated remote attacker can cause denial of service by exhausting the node's memory through repeated opening of unhandled session channels. This results in termination of the Erlang emulator, affecting all applications running on the node. There is no exposure of file contents, credentials, or write access.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vulnerability requires authentication and exploits a resource exhaustion condition, monitor for unusual SSH session channel activity and consider limiting authenticated user access until a fix is applied.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-68956
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab4be55f7a7c54106f0aa42
Added to database: 09/24/2026, 06:08:21 UTC
Last enriched: 09/24/2026, 06:47:08 UTC
Last updated: 09/25/2026, 02:47:33 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.