PT-2026-84269 · Erlang · Otp+1

·

CVE-2026-75538

·

Published

2026-09-01

·

Updated

2026-09-02

CVSS v4.0

8.2

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions OTP versions 17.0 through 27.3.4.16 OTP versions 28.0 through 28.5.0.5 OTP versions 29.0 through 29.0.5 erts versions 6.0 through 15.2.7.12 erts versions 16.0 through 16.4.0.5 erts versions 17.0 through 17.0.5
Description An attacker connecting to an open Erlang TCP port using the inet driver with {packet,4} mode can trigger a signed overflow due to an incorrect packet length calculation. This allows the receive buffer to overflow into the VM allocator area and beyond by up to 2 GB, which typically corrupts the allocator metadata footer and subsequent blocks, leading to a BEAM VM crash. Achieving Remote Code Execution through this method is considered extremely unfeasible.
Recommendations Update OTP to version 27.3.4.17 or later. Update OTP to version 28.5.0.6 or later. Update OTP to version 29.0.6 or later. Update erts to version 15.2.7.13 or later. Update erts to version 16.4.0.6 or later. Update erts to version 17.0.6 or later.

Exploit

Fix

RCE

Heap Based Buffer Overflow

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-98499
CVE-2026-75538
GHSA-8M6R-2PJ2-25PM

Affected Products

Otp
Erts