Description
An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an incorrect packet length calculation to overflow the receive buffer into the VM allocator area and beyond up to about 2 GB.

This would easily trash the allocated block's allocator metadata footer, and the next block, if any, and most likely cause the BEAM VM to crash. Utilizing this with precision enough to achieve Remote Code Execution would be extremely unfeasible.

This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to erts from 6.0 before 15.2.7.13, from 16.0 before 16.4.0.6, and from 17.0 before 17.0.6. Whether OTP before OTP 17.0, corresponding to erts before 6.0, is affected is unknown.
Published: 2026-09-01
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

A signed integer overflow in Erlang/OTP's inet TCP driver allows an unauthenticated attacker to send a specially crafted packet to a service running with {packet,4} mode. The overflow corrupts the receive buffer and propagates the overflow into the BEAM VM's allocator metadata up to around 2 GB, which in practice causes the BEAM VM to crash. The vulnerability does not provide a straightforward remote code execution path, so its primary impact is a denial‑of‑service on the affected node.

Affected Systems

The flaw is present in Erlang/OTP releases up to OTP 27.3.4.17, up to OTP 28.5.0.6, and up to OTP 29.0.6, including the corresponding erts releases before these patch points. In short, any Erlang/OTP install that does not incorporate the commit fixing the overflow is potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.2 labels the issue as high severity, and despite the EPSS score being unavailable the nature of the overflow indicates a non‑trivial exploit effort. The vulnerability is publicly exploitable over an open network port, but the lack of a reliable remote‑code‑execution path and the need for precise packet crafting reduce the likelihood of large‑scale deployment. It is not listed in the CISA KEV catalog, which further suggests that no widespread active exploitation has been observed yet.

Generated by OpenCVE AI on September 1, 2026 at 16:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Erlang/OTP 27.3.4.17, 28.5.0.6, or 29.0.6 or later, which contain a fixed inet driver.
  • If upgrade is not immediately feasible, restrict access to any TCP ports that use {packet,4} so that only trusted hosts can connect.
  • Consider switching the inet driver configuration away from {packet,4} to a safer mode such as {packet,0} or disabling the packet setting where appropriate.

Generated by OpenCVE AI on September 1, 2026 at 16:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Erlang erlang/otp
Erlang otp
Vendors & Products Erlang erlang/otp
Erlang otp
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 01 Sep 2026 15:00:00 +0000

Type Values Removed Values Added
Description An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an incorrect packet length calculation to overflow the receive buffer into the VM allocator area and beyond up to about 2 GB. This would easily trash the allocated block's allocator metadata footer, and the next block, if any, and most likely cause the BEAM VM to crash. Utilizing this with precision enough to achieve Remote Code Execution would be extremely unfeasible. This issue affects OTP from OTP 17.0 before OTP 27.3.4.17, from OTP 28.0 before OTP 28.5.0.6, and from OTP 29.0 before OTP 29.0.6, corresponding to erts from 6.0 before 15.2.7.13, from 16.0 before 16.4.0.6, and from 17.0 before 17.0.6. Whether OTP before OTP 17.0, corresponding to erts before 6.0, is affected is unknown.
Title A Signed Length Overflow in Erlang/OTP's inet TCP Driver Overflows the Receive Buffer Into BEAM VM Memory From an Unauthenticated Peer
First Time appeared Erlang
Erlang erlang\/otp
Weaknesses CWE-122
CWE-190
CPEs cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
Vendors & Products Erlang
Erlang erlang\/otp
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Erlang Erlang/otp Erlang\/otp Otp
cve-icon MITRE

Status: PUBLISHED

Assigner: EEF

Published:

Updated: 2026-09-08T01:10:53.139Z

Reserved: 2026-08-20T10:15:01.237Z

Link: CVE-2026-75538

cve-icon Vulnrichment

Updated: 2026-09-01T15:58:14.389Z

cve-icon NVD

Status : Deferred

Published: 2026-09-01T15:17:26.853

Modified: 2026-09-08T02:17:27.870

Link: CVE-2026-75538

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T18:15:04Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow

  • CWE-190

    Integer Overflow or Wraparound