Impact
A stack-based buffer overflow exists in the inet_drv SCTP error chunk parser in Erlang OTP’s runtime system (ERTS). The sctp_parse_error_chunk function writes cause codes into a fixed-size array on the stack without bounds checking, a vulnerability that aligns with CWE-120 and CWE-121. The likely attack vector is an unauthenticated remote attacker establishing an SCTP association with a listening port to send a crafted SCTP ERROR chunk. An attacker can send a crafted SCTP ERROR chunk with an excessive number of cause codes. This overflow crashes the BEAM virtual machine but does not provide a controllable return address, so the primary outcome is a loss of availability. Additionally, an attacker may observe partial Erlang VM memory in the error packet, but the disclosed data is already readable by the user running the VM, limiting the scope of disclosure.
Affected Systems
The vulnerability affects Erlang OTP releases from 17.0 up to but excluding 27.3.4.13, as well as OTP 28.5.0.2 and 29.0.2. The corresponding runtime system versions are erts 6.0 through 15.2.7.9, 16.4.0.2, and 17.0.2. Version 17.0 and earlier (erts 6.0 and below) are not confirmed to be affected.
Risk and Exploitability
The CVSS score of 8.8 classifies the flaw as high severity, indicating a significant impact if exploited. The EPSS score of <1% suggests that exploitation is currently unlikely in the wild, yet the flaw requires no privileged credentials or authentication, making it reachable from any network that can establish an SCTP association to a listening port. The vulnerability is not listed in CISA’s KEV catalog and, as of the last advisory, no active exploits are publicly documented.
OpenCVE Enrichment
Debian DSA