An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an incorrect packet… (CVE-2026-75538)
A vulnerability in Erlang's inet driver when using {packet,4} mode allows an attacker connecting to an open TCP port to cause a signed overflow in packet length calculation. This overflow can corrupt the receive buffer and allocator metadata, likely causing the BEAM VM to crash. Exploitation for remote code execution is considered extremely unlikely. The issue affects multiple OTP and erts versions prior to specific fixed releases. Patches are available and have been released by Ubuntu.
AI Analysis
Technical Summary
CVE-2026-75538 is a vulnerability in Erlang's inet driver with {packet,4} mode where an attacker can send a specially crafted packet causing a signed overflow in the packet length calculation. This overflow leads to buffer overflow into the VM allocator area, corrupting allocator metadata and potentially crashing the BEAM VM. Achieving remote code execution through this vulnerability is highly improbable. The flaw affects OTP versions from 17.0 before 27.3.4.17, 28.0 before 28.5.0.6, and 29.0 before 29.0.6, corresponding to erts versions 6.0 before 15.2.7.13, 16.0 before 16.4.0.6, and 17.0 before 17.0.6. Ubuntu has released patches addressing this vulnerability in multiple LTS releases.
Potential Impact
An attacker who can connect to an open Erlang TCP port using the inet driver with {packet,4} mode can cause a buffer overflow that corrupts memory allocator metadata, leading to a denial of service via a crash of the BEAM VM. The vulnerability does not realistically allow remote code execution. The primary impact is a denial of service condition.
Mitigation Recommendations
A patch is available and should be applied. Ubuntu has released fixed package versions for multiple LTS releases as detailed in their security notice USN-8827-1. Updating Erlang packages to these fixed versions and rebooting the system is the recommended remediation.
An attacker that connects to an open Erlang TCP port that uses the inet driver with {packet,4} mode can use a signed overflow in an incorrect packet… (CVE-2026-75538)
Description
A vulnerability in Erlang's inet driver when using {packet,4} mode allows an attacker connecting to an open TCP port to cause a signed overflow in packet length calculation. This overflow can corrupt the receive buffer and allocator metadata, likely causing the BEAM VM to crash. Exploitation for remote code execution is considered extremely unlikely. The issue affects multiple OTP and erts versions prior to specific fixed releases. Patches are available and have been released by Ubuntu.
CVSS v4.0
Affected software
pkg:deb/ubuntu/erlang?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/erlang?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/erlang?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/erlang?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/erlang?arch=source&distro=jammypkg:deb/ubuntu/erlang?arch=source&distro=noblepkg:deb/ubuntu/erlang?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-75538 is a vulnerability in Erlang's inet driver with {packet,4} mode where an attacker can send a specially crafted packet causing a signed overflow in the packet length calculation. This overflow leads to buffer overflow into the VM allocator area, corrupting allocator metadata and potentially crashing the BEAM VM. Achieving remote code execution through this vulnerability is highly improbable. The flaw affects OTP versions from 17.0 before 27.3.4.17, 28.0 before 28.5.0.6, and 29.0 before 29.0.6, corresponding to erts versions 6.0 before 15.2.7.13, 16.0 before 16.4.0.6, and 17.0 before 17.0.6. Ubuntu has released patches addressing this vulnerability in multiple LTS releases.
Potential Impact
An attacker who can connect to an open Erlang TCP port using the inet driver with {packet,4} mode can cause a buffer overflow that corrupts memory allocator metadata, leading to a denial of service via a crash of the BEAM VM. The vulnerability does not realistically allow remote code execution. The primary impact is a denial of service condition.
Mitigation Recommendations
A patch is available and should be applied. Ubuntu has released fixed package versions for multiple LTS releases as detailed in their security notice USN-8827-1. Updating Erlang packages to these fixed versions and rebooting the system is the recommended remediation.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-75538
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:26.04:LTS"]
- Cvss Version
- 4.0
- State
- PUBLISHED
Patch Information
Threat ID: 6abb4193f7a7c54106cc37fd
Added to database: 09/29/2026, 04:41:55 UTC
Last enriched: 09/29/2026, 04:50:12 UTC
Last updated: 09/29/2026, 18:13:09 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.