Stack-based Buffer Overflow Vulnerability in Erlang OTP Product by Erlang
CVE-2026-49759

8.8HIGH

Key Information:

Vendor

Erlang

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2026-49759?

A stack-based buffer overflow vulnerability in Erlang OTP's erts component can be exploited by unauthenticated remote attackers. By sending a specially crafted SCTP ERROR chunk, an attacker can overflow the fixed-size stack-allocated buffer within the sctp_parse_error_chunk function, leading to a crash of the Erlang VM. Although this effectively results in a Denial of Service, the limitations of the exploit mean that attackers cannot control the return address within the stack. Additionally, this attack may leak parts of the Erlang VM memory into the SCTP ERROR packet, although sensitive data exposure is limited since this information can already be accessed by the user running the Erlang VM. Affected versions include OTP from 17.0 up until 27.3.4.13, as well as specific builds in the later 28 and 29 series.

Affected Version(s)

OTP 6.0

OTP 17.0

OTP 84adefa331c4159d432d22840663c38f155cd4c1 < 3983d495284331c121f600a80bac9fcf4e16381e

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Zhang Delong
Raimo Niskanen
.