KEX init error results with excessive memory usage
Package
No package listed
Affected versions
< OTP-27.3.1
< OTP-26.2.5.10
< OTP-25.3.2.19
Patched versions
OTP-27.3.1
OTP-26.2.5.10
OTP-25.3.2.19
Impact
Maliciously formed KEX init message can result with high memory usage.
Implementation does not verify RFC specified limits on algorithm names (64 characters) provided in KEX init message.
Big KEX init packet may lead to inefficient processing of the error data. As a result, large amount of memory will be allocated for processing malicious data.
Patches
Workarounds
parallel_login
tofalse
max_sessions
optionReferences
n/a