Buffer Overflow Vulnerability in Erlang OTP by Erlang Solutions
CVE-2026-75538
8.2HIGH
What is CVE-2026-75538?
An attacker exploiting an open Erlang TCP port using the inet driver with {packet,4} mode may leverage a signed overflow due to inaccurate packet length calculations. This overflow can corrupt the receive buffer, potentially impacting the VM allocator area and leading to severe instability, including the possible crashing of the BEAM VM. Although utilizing this vulnerability for Remote Code Execution is deemed extremely challenging, it underscores a significant risk that needs addressing. The affected versions include Erlang OTP from 17.0 to 27.3.4.17, 28.0 to 28.5.0.6, and 29.0 to 29.0.6, among others.
Affected Version(s)
OTP 17.0 < 27.3.4.17
OTP 28.0 < 28.5.0.6
OTP 29.0 < 29.0.6
References
CVSS V4
Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Arthur Chan
David Korczynski
Adam Korcz
RaimoNiskanen / Ericsson
Sverker Eriksson / Ericsson
John Högberg / Ericsson
