Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-75538

Erlang/OTP inet driver {packet,4} length overflow writes past the receive buffer

Technology

Erlang/OTP

CVSS Score

8.2 / 10.0

Affected Versions

OTP 17.0 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (erts)

Upstream Fix

OTP 27.3.4.17, 28.5.0.6, 29.0.6

Published

September 1, 2026

OSSeva Coverage

Fixed upstream

Description

A signed overflow in the packet length calculation of the inet driver in {packet,4} mode lets anyone who connects to such a port overflow the receive buffer into the VM allocator area, which most likely crashes the BEAM VM. The advisory calls remote code execution through it extremely unfeasible.

Upstream record: NVD · CVE.org

Is your Erlang/OTP deployment affected?

If you're running OTP 17.0 and later, before 27.3.4.17, 28.5.0.6 and 29.0.6 (erts), you need this patch. Book a discovery call to get covered.