Buffer Overflow in Erlang/OTP Megaco Flex Scanner C Driver
CVE-2026-59250
What is CVE-2026-59250?
A classic buffer overflow vulnerability exists in the Erlang/OTP Megaco flex scanner C driver, allowing a remote unauthenticated attacker to corrupt memory by sending a specially crafted H.248/Megaco message. The overflow occurs due to the improper handling of oversized property names, which can lead to arbitrary memory manipulation and potential remote code execution. The vulnerable code is executed prior to any authentication, making exploitation feasible for attackers with network access to the affected service. Certain build configurations may trigger runtime protections that terminate the process, resulting in a denial-of-service condition instead.
Affected Version(s)
OTP 17.0 < 27.3.4.15
OTP 28.0 < 28.5.0.4
OTP 29.0 < 29.0.4
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
