Stack-based Buffer Overflow Vulnerability in Erlang OTP Product by Erlang
CVE-2026-49759
What is CVE-2026-49759?
A stack-based buffer overflow vulnerability in Erlang OTP's erts component can be exploited by unauthenticated remote attackers. By sending a specially crafted SCTP ERROR chunk, an attacker can overflow the fixed-size stack-allocated buffer within the sctp_parse_error_chunk function, leading to a crash of the Erlang VM. Although this effectively results in a Denial of Service, the limitations of the exploit mean that attackers cannot control the return address within the stack. Additionally, this attack may leak parts of the Erlang VM memory into the SCTP ERROR packet, although sensitive data exposure is limited since this information can already be accessed by the user running the Erlang VM. Affected versions include OTP from 17.0 up until 27.3.4.13, as well as specific builds in the later 28 and 29 series.
Affected Version(s)
OTP 6.0
OTP 17.0
OTP 84adefa331c4159d432d22840663c38f155cd4c1 < 3983d495284331c121f600a80bac9fcf4e16381e
