CWE-121 Stack-based Buffer Overflow in Erlang OTP (CVE-2026-49759)
CVE-2026-49759 is a stack-based buffer overflow vulnerability in the Erlang OTP erts inet_drv component. It allows an unauthenticated remote attacker to crash the Erlang BEAM VM by sending a specially crafted SCTP ERROR chunk. The vulnerability arises from improper bounds checking when parsing SCTP ERROR chunks, leading to stack overflow. While the overflow can cause a denial of service, it does not allow controlled code execution. Some memory disclosure may occur but is limited to data already accessible by the Erlang VM user. This affects OTP versions from 17.0 before 27.3.4.13, 28.5.0.2, and 29.0.2, corresponding to erts versions from 6.0 before 15.2.7.9, 16.4.0.2, and 17.0.2.
AI Analysis
Technical Summary
The vulnerability CVE-2026-49759 is a stack-based buffer overflow in the sctp_parse_error_chunk function of the Erlang OTP erts inet_drv module. This function parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated array without proper bounds checking. An attacker who has established an SCTP association can send a crafted SCTP ERROR chunk with enough cause codes to overflow this stack buffer, causing the BEAM VM to crash. The overflow only allows writing 16-bit values interleaved with a fixed tag, preventing controlled return address manipulation and limiting exploitation to denial of service. Additionally, the crafted chunk may leak fragments of Erlang VM memory in the error packet, but this data is already accessible to the user running the VM, limiting the impact of information disclosure. The affected versions include OTP from 17.0 up to but not including 27.3.4.13, 28.5.0.2, and 29.0.2, and corresponding erts versions from 6.0 up to but not including 15.2.7.9, 16.4.0.2, and 17.0.2.
Potential Impact
An unauthenticated remote attacker can cause a denial of service by crashing the Erlang BEAM VM through a stack-based buffer overflow triggered by a crafted SCTP ERROR chunk. The vulnerability does not allow code execution or privilege escalation. Limited information disclosure may occur but only exposes memory already accessible to the Erlang VM user, so it does not increase the risk of sensitive data leakage beyond existing permissions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official patch or fix links are provided in the available data. Users should monitor the Erlang and Red Hat advisories for updates and apply any official fixes once released. In the meantime, restricting SCTP access to trusted sources and limiting exposure of Erlang services using SCTP may reduce risk.
CWE-121 Stack-based Buffer Overflow in Erlang OTP (CVE-2026-49759)
Description
CVE-2026-49759 is a stack-based buffer overflow vulnerability in the Erlang OTP erts inet_drv component. It allows an unauthenticated remote attacker to crash the Erlang BEAM VM by sending a specially crafted SCTP ERROR chunk. The vulnerability arises from improper bounds checking when parsing SCTP ERROR chunks, leading to stack overflow. While the overflow can cause a denial of service, it does not allow controlled code execution. Some memory disclosure may occur but is limited to data already accessible by the Erlang VM user. This affects OTP versions from 17.0 before 27.3.4.13, 28.5.0.2, and 29.0.2, corresponding to erts versions from 6.0 before 15.2.7.9, 16.4.0.2, and 17.0.2.
CVSS v4.0
Score 8.8high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-49759 is a stack-based buffer overflow in the sctp_parse_error_chunk function of the Erlang OTP erts inet_drv module. This function parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated array without proper bounds checking. An attacker who has established an SCTP association can send a crafted SCTP ERROR chunk with enough cause codes to overflow this stack buffer, causing the BEAM VM to crash. The overflow only allows writing 16-bit values interleaved with a fixed tag, preventing controlled return address manipulation and limiting exploitation to denial of service. Additionally, the crafted chunk may leak fragments of Erlang VM memory in the error packet, but this data is already accessible to the user running the VM, limiting the impact of information disclosure. The affected versions include OTP from 17.0 up to but not including 27.3.4.13, 28.5.0.2, and 29.0.2, and corresponding erts versions from 6.0 up to but not including 15.2.7.9, 16.4.0.2, and 17.0.2.
Potential Impact
An unauthenticated remote attacker can cause a denial of service by crashing the Erlang BEAM VM through a stack-based buffer overflow triggered by a crafted SCTP ERROR chunk. The vulnerability does not allow code execution or privilege escalation. Limited information disclosure may occur but only exposes memory already accessible to the Erlang VM user, so it does not increase the risk of sensitive data leakage beyond existing permissions.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official patch or fix links are provided in the available data. Users should monitor the Erlang and Red Hat advisories for updates and apply any official fixes once released. In the meantime, restricting SCTP access to trusted sources and limiting exposure of Erlang services using SCTP may reduce risk.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_vex
- Csaf Version
- 2.0
- Publisher
- Microsoft Security Response Center
- Advisory Id
- msrc_CVE-2026-49759
- Cve Count
- 1
- Additional Cves
- []
- Cvss Version
- null
Threat ID: 6a359350f198dc38c1067094
Added to database: 06/19/2026, 19:06:56 UTC
Last enriched: 07/15/2026, 15:36:46 UTC
Last updated: 07/31/2026, 19:24:47 UTC
Views: 242
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.