Impact
A stack-based buffer overflow in the SCTP error chunk parser of Erlang OTP erts (inet_drv) can cause the BEAM virtual machine to crash when an attacker sends a crafted SCTP ERROR message. The overflow writes 16‑bit cause codes into a fixed‑size array without bounds checking, limiting the attack to a denial of service rather than arbitrary code execution. Leakage of small chunks of memory is possible but is viewable only by the user owning the Erlang VM, so confidentiality impact is minimal.
Affected Systems
The vulnerability affects Erlang OTP versions 17.0 through 27.3.4.12, 28.5.0.1, and 29.0.1, corresponding to erts releases 6.0 through 15.2.7.8, 16.4.0.1 and 17.0.1. It is present in the Erlang:OTP product family and is referenced by the Erlang Community Network Authority.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity denial of service flaw. No EPSS score is available, but the absence of a requirement for privileged access or authentication suggests the attack vector is network based, via an SCTP association to a listening port. The vulnerability is not listed in CISA’s KEV catalog and currently has no known exploits in the wild.
OpenCVE Enrichment