Skip to main content
EPSS 0.8%top 46%

CVE-2026-59250: CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') in Erlang OTP

0
High
Published: 07/27/2026 (07/27/2026, 15:25:03 UTC)
Source: CVE Database V5
Vendor/Project: Erlang
Product: OTP

Description

Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and potentially achieve remote code execution or a denial-of-service crash) by sending a single text-encoded H.248/Megaco message containing an oversized property parm name. When tokenizing a Local/Remote descriptor, mfs_load_property_groups extracts the attacker-controlled property name (bounded only by the message length) and, when no value follows, formats it into a fixed 512-byte error_msg field of the MfsErlDrvData struct using an unchecked sprintf call. Names longer than roughly 452 bytes overflow into the immediately following struct fields (text_buf, text_ptr, term_spec, term_spec_size, term_spec_index), overwriting live pointers and counters with attacker-chosen bytes. Subsequent scanner code writes and frees through the corrupted pointers, producing arbitrary write and arbitrary free primitives inside the BEAM VM process, which can be leveraged for remote code execution. On builds compiled with _FORTIFY_SOURCE the overflow is detected at runtime and terminates the process with SIGABRT, resulting in denial of service. The overflow occurs in the flex scanner before any grammar or Megaco-level authentication processing, so exploitation requires only network reachability to the megaco transport port on a node configured with {scanner, flex}. This vulnerability is associated with program files lib/megaco/src/flex/megaco_flex_scanner_drv.flex.src and program routines mfs_load_property_groups. This issue affects OTP from OTP 17.0 before OTP 27.3.4.15, from OTP 28.0 before OTP 28.5.0.4, and from OTP 29.0 before OTP 29.0.4, corresponding to megaco from 3.17.1 before 4.7.2.2, from 4.8 before 4.8.3.1, and from 4.9 before 4.9.1. Whether OTP before OTP 17.0, corresponding to megaco before 3.17.1, is affected is unknown.

CVSS v4.0

Score 8.3high

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
Low
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N

Affected software

Erlang

OTP

GitHub Actionsmore threats →cve
megaco
pkg:github/megaco
Affected versions
>=3.17.1 <4.7.2.2>=4.8 <4.8.3.1>=4.9 <4.9.1
GitHub Actionsmore threats →cve
erlang/otp
pkg:github/erlang/otp
CPE configurations
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 17:18:24 UTC

Technical Analysis

This vulnerability is a buffer overflow in the Erlang/OTP megaco flex scanner C driver, specifically in the function mfs_load_property_groups. When processing a Local/Remote descriptor, the driver extracts a property name from an attacker-controlled message without properly checking its size. If the property name exceeds approximately 452 bytes, it overflows a fixed 512-byte buffer (error_msg field) in the MfsErlDrvData struct via an unchecked sprintf call. This overflow corrupts adjacent struct fields, including pointers and counters, leading to arbitrary memory write and free operations. These primitives can be exploited for remote code execution within the BEAM VM process. On systems compiled with _FORTIFY_SOURCE, the overflow triggers a runtime abort (SIGABRT), causing denial of service. The vulnerability is exploitable remotely without authentication, requiring only network reachability to the megaco transport port on nodes configured with {scanner, flex}. Affected versions include OTP from 17.0 before 29.0.4, 28.5.0.4, and 27.3.4.15, and megaco from 3.17.1 before 4.9.1, 4.8.3.1, and 4.7.2.2.

Potential Impact

Successful exploitation allows a remote unauthenticated attacker to corrupt memory in the Erlang/OTP megaco flex scanner driver, potentially leading to remote code execution or denial of service by crashing the process. The vulnerability occurs before any authentication or grammar processing, making it exploitable solely via network access to the megaco transport port. On hardened builds with _FORTIFY_SOURCE, exploitation results in process termination (denial of service) rather than code execution.

Mitigation Recommendations

Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict network access to the megaco transport port on nodes configured with {scanner, flex} to trusted sources only. Monitor for updates from the Erlang/OTP project regarding official patches or mitigations.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
EEF
Date Reserved
2026-07-04T04:24:03.653Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 6a677b469c2644c7f8512894

Added to database: 07/27/2026, 15:37:42 UTC

Last enriched: 08/15/2026, 17:18:24 UTC

Last updated: 09/10/2026, 18:10:37 UTC

Views: 85

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses