erlang: Erlang OTP: Denial of Service via crafted SCTP ERROR chunk

cve CVE-2026-49759 2 sources, 2 claims · Watch

Red Hat writes:
erlang: Erlang OTP: Denial of Service via crafted SCTP ERROR chunk the claim
Severity
HIGH NVD
important Red Hat
CVSS
8.2 NVD
8.2 Red Hat
Vendor
Erlang NVD
Product
OTP NVD
CWE
CWE-121, CWE-120 NVD
CWE-120 Red Hat

How far exploitation has got

  1. No public code known
  2. Proof of concept
  3. Proof of concept, verified
  4. A Metasploit module
  5. Exploited in the wild
  6. Used in ransomware campaigns

Timeline

2026-06-10first spoke of it: Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk. The sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a single crafted SCTP ERROR chunk containing enough cause codes to overflow the stack buffer, crashing the VM. The attacker can only write 16-bit values interleaved with a fixed tag, so the overflow does not provide a controlled return address, limiting exploitation to Denial of Service. A crafted SCTP ERROR chunk may also leak bits and pieces of Erlang VM memory into the received error packet observed by the Erlang process. Such data is already readable by the user running the Erlang VM, so the disclosure scope is limited. This issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to erts from 6.0 before 15.2.7.9, 16.4.0.2, and 17.0.2. Whether OTP before OTP 17.0, corresponding to erts before 6.0, is affected is unknown.NVD
2026-06-10first spoke of it: erlang: Erlang OTP: Denial of Service via crafted SCTP ERROR chunkRed Hat

What it is to other things

affectserlang/erlang\/otp
NVD
affectserlang/erts
NVD
made_byerlang
NVD

In words only, so not counted until a person confirms one:

affectserlang/otp
NVD says “Erlang · OTP”
Every value, with what each source said and its receipt
PropertySourceSaidMeans here
Automatable
automatable
NVDyes
An attacker can reliably run all of the kill chain's first four steps without a person.
receipt
Source
NVD
Its words
yes
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].automatable
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCyes
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "otp",
            "packageURL": "pkg:software-id/erlang.org/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "27.3.4.13",
                    "status": "unaffected"
                  },
                  {
                    "at": "28.5.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "29.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "17.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erts",
            "packageURL": "pkg:otp/erts?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
            "product": "OTP",
            "programFiles": [
              "emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "15.2.7.9",
                    "status": "unaffected"
                  },
                  {
                    "at": "16.4.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "17.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "6.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erlang/otp",
            "packageURL": "pkg:github/erlang/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "lessThan": "3983d495284331c121f600a80bac9fcf4e16381e",
                "status": "affected",
                "version": "84adefa331c4159d432d22840663c38f155cd4c1",
                "versionType": "git"
              },
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "3983d495284331c121f600a80bac9fcf4e16381e",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      },
      {
        "affectedData": [
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:16.2"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 16.2",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:17.1"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 17.1",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:18.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 18.0",
            "vendor": "Red Hat"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BF42A5F2-4C27-43FE-B5FA-17A3422B9649",
                "versionEndExcluding": "27.3.4.13",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
                "versionEndExcluding": "28.5.0.2",
                "versionStartIncluding": "28.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
                "versionEndExcluding": "29.0.2",
                "versionStartIncluding": "29.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EAB60C9A-F1B2-4377-8C9B-B8496D3D9B5C",
                "versionEndExcluding": "15.2.7.9",
                "versionStartIncluding": "6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0778AFBA-F21F-4394-AA3A-38784D379BEB",
                "versionEndExcluding": "16.4.0.2",
                "versionStartIncluding": "16.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "05F0E6B1-0DA3-4A0B-8C89-8DFC55EC7C8B",
                "versionEndExcluding": "17.0.2",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk.\n\nThe sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a single crafted SCTP ERROR chunk containing enough cause codes to overflow the stack buffer, crashing the VM. The attacker can only write 16-bit values interleaved with a fixed tag, so the overflow does not provide a controlled return address, limiting exploitation to Denial of Service.\n\nA crafted SCTP ERROR chunk may also leak bits and pieces of Erlang VM memory into the received error packet observed by the Erlang process. Such data is already readable by the user running the Erlang VM, so the disclosure scope is limited.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to erts from 6.0 before 15.2.7.9, 16.4.0.2, and 17.0.2. Whether OTP before OTP 17.0, corresponding to erts before 6.0, is affected is unknown."
      }
    ],
    "id": "CVE-2026-49759",
    "lastModified": "2026-09-24T21:17:14.810",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-49759",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-10T16:18:27.945916Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-10T16:17:12.797",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cna.erlef.org/cves/CVE-2026-49759.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/erlang/otp/commit/3983d495284331c121f600a80bac9fcf4e16381e"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/erlang/otp/security/advisories/GHSA-6f4f-chj5-5g97"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://osv.dev/vulnerability/EEF-CVE-2026-49759"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Product"
        ],
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://access.redhat.com/security/cve/CVE-2026-49759"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487607"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49759.json"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-121"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-120"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
NVD8.2
receipt
Source
NVD
Its words
8.2
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "otp",
            "packageURL": "pkg:software-id/erlang.org/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "27.3.4.13",
                    "status": "unaffected"
                  },
                  {
                    "at": "28.5.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "29.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "17.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erts",
            "packageURL": "pkg:otp/erts?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
            "product": "OTP",
            "programFiles": [
              "emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "15.2.7.9",
                    "status": "unaffected"
                  },
                  {
                    "at": "16.4.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "17.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "6.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erlang/otp",
            "packageURL": "pkg:github/erlang/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "lessThan": "3983d495284331c121f600a80bac9fcf4e16381e",
                "status": "affected",
                "version": "84adefa331c4159d432d22840663c38f155cd4c1",
                "versionType": "git"
              },
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "3983d495284331c121f600a80bac9fcf4e16381e",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      },
      {
        "affectedData": [
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:16.2"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 16.2",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:17.1"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 17.1",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:18.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 18.0",
            "vendor": "Red Hat"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BF42A5F2-4C27-43FE-B5FA-17A3422B9649",
                "versionEndExcluding": "27.3.4.13",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
                "versionEndExcluding": "28.5.0.2",
                "versionStartIncluding": "28.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
                "versionEndExcluding": "29.0.2",
                "versionStartIncluding": "29.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EAB60C9A-F1B2-4377-8C9B-B8496D3D9B5C",
                "versionEndExcluding": "15.2.7.9",
                "versionStartIncluding": "6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0778AFBA-F21F-4394-AA3A-38784D379BEB",
                "versionEndExcluding": "16.4.0.2",
                "versionStartIncluding": "16.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "05F0E6B1-0DA3-4A0B-8C89-8DFC55EC7C8B",
                "versionEndExcluding": "17.0.2",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk.\n\nThe sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a single crafted SCTP ERROR chunk containing enough cause codes to overflow the stack buffer, crashing the VM. The attacker can only write 16-bit values interleaved with a fixed tag, so the overflow does not provide a controlled return address, limiting exploitation to Denial of Service.\n\nA crafted SCTP ERROR chunk may also leak bits and pieces of Erlang VM memory into the received error packet observed by the Erlang process. Such data is already readable by the user running the Erlang VM, so the disclosure scope is limited.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to erts from 6.0 before 15.2.7.9, 16.4.0.2, and 17.0.2. Whether OTP before OTP 17.0, corresponding to erts before 6.0, is affected is unknown."
      }
    ],
    "id": "CVE-2026-49759",
    "lastModified": "2026-09-24T21:17:14.810",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-49759",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-10T16:18:27.945916Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-10T16:17:12.797",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cna.erlef.org/cves/CVE-2026-49759.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/erlang/otp/commit/3983d495284331c121f600a80bac9fcf4e16381e"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/erlang/otp/security/advisories/GHSA-6f4f-chj5-5g97"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://osv.dev/vulnerability/EEF-CVE-2026-49759"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Product"
        ],
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://access.redhat.com/security/cve/CVE-2026-49759"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487607"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49759.json"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-121"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-120"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS
cvss
Red Hat8.2
receipt
Source
Red Hat
Its words
8.2
Read by
field:cvss3_score
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-49759",
  "CWE": "CWE-120",
  "advisories": [
    "RHSA-2026:63160"
  ],
  "affected_packages": [
    "erlang27-main-27.3.4.17-1.hum1"
  ],
  "bugzilla": "2487607",
  "bugzilla_description": "erlang: Erlang OTP: Denial of Service via crafted SCTP ERROR chunk",
  "cvss3_score": "8.2",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-10T14:35:38Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-49759.json",
  "severity": "important"
}
—
Cvss4
cvss4
NVD8.8
receipt
Source
NVD
Its words
8.8
Read by
field:cve.metrics.cvssMetricV40[type=Primary].cvssData.baseScore || field:cve.metrics.cvssMetricV40[].cvssData.baseScore
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTC8.8
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "otp",
            "packageURL": "pkg:software-id/erlang.org/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "27.3.4.13",
                    "status": "unaffected"
                  },
                  {
                    "at": "28.5.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "29.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "17.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erts",
            "packageURL": "pkg:otp/erts?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
            "product": "OTP",
            "programFiles": [
              "emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "15.2.7.9",
                    "status": "unaffected"
                  },
                  {
                    "at": "16.4.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "17.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "6.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erlang/otp",
            "packageURL": "pkg:github/erlang/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "lessThan": "3983d495284331c121f600a80bac9fcf4e16381e",
                "status": "affected",
                "version": "84adefa331c4159d432d22840663c38f155cd4c1",
                "versionType": "git"
              },
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "3983d495284331c121f600a80bac9fcf4e16381e",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      },
      {
        "affectedData": [
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:16.2"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 16.2",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:17.1"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 17.1",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:18.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 18.0",
            "vendor": "Red Hat"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BF42A5F2-4C27-43FE-B5FA-17A3422B9649",
                "versionEndExcluding": "27.3.4.13",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
                "versionEndExcluding": "28.5.0.2",
                "versionStartIncluding": "28.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
                "versionEndExcluding": "29.0.2",
                "versionStartIncluding": "29.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EAB60C9A-F1B2-4377-8C9B-B8496D3D9B5C",
                "versionEndExcluding": "15.2.7.9",
                "versionStartIncluding": "6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0778AFBA-F21F-4394-AA3A-38784D379BEB",
                "versionEndExcluding": "16.4.0.2",
                "versionStartIncluding": "16.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "05F0E6B1-0DA3-4A0B-8C89-8DFC55EC7C8B",
                "versionEndExcluding": "17.0.2",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk.\n\nThe sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a single crafted SCTP ERROR chunk containing enough cause codes to overflow the stack buffer, crashing the VM. The attacker can only write 16-bit values interleaved with a fixed tag, so the overflow does not provide a controlled return address, limiting exploitation to Denial of Service.\n\nA crafted SCTP ERROR chunk may also leak bits and pieces of Erlang VM memory into the received error packet observed by the Erlang process. Such data is already readable by the user running the Erlang VM, so the disclosure scope is limited.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to erts from 6.0 before 15.2.7.9, 16.4.0.2, and 17.0.2. Whether OTP before OTP 17.0, corresponding to erts before 6.0, is affected is unknown."
      }
    ],
    "id": "CVE-2026-49759",
    "lastModified": "2026-09-24T21:17:14.810",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-49759",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-10T16:18:27.945916Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-10T16:17:12.797",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cna.erlef.org/cves/CVE-2026-49759.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/erlang/otp/commit/3983d495284331c121f600a80bac9fcf4e16381e"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/erlang/otp/security/advisories/GHSA-6f4f-chj5-5g97"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://osv.dev/vulnerability/EEF-CVE-2026-49759"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Product"
        ],
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://access.redhat.com/security/cve/CVE-2026-49759"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487607"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49759.json"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-121"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-120"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "type": "Secondary"
      }
    ]
  }
}
—
Cvss4 vector
cvss4_vector
NVDCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
receipt
Source
NVD
Its words
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Read by
field:cve.metrics.cvssMetricV40[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV40[].cvssData.vectorString
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "otp",
            "packageURL": "pkg:software-id/erlang.org/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "27.3.4.13",
                    "status": "unaffected"
                  },
                  {
                    "at": "28.5.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "29.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "17.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erts",
            "packageURL": "pkg:otp/erts?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
            "product": "OTP",
            "programFiles": [
              "emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "15.2.7.9",
                    "status": "unaffected"
                  },
                  {
                    "at": "16.4.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "17.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "6.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erlang/otp",
            "packageURL": "pkg:github/erlang/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "lessThan": "3983d495284331c121f600a80bac9fcf4e16381e",
                "status": "affected",
                "version": "84adefa331c4159d432d22840663c38f155cd4c1",
                "versionType": "git"
              },
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "3983d495284331c121f600a80bac9fcf4e16381e",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      },
      {
        "affectedData": [
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:16.2"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 16.2",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:17.1"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 17.1",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:18.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 18.0",
            "vendor": "Red Hat"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BF42A5F2-4C27-43FE-B5FA-17A3422B9649",
                "versionEndExcluding": "27.3.4.13",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
                "versionEndExcluding": "28.5.0.2",
                "versionStartIncluding": "28.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
                "versionEndExcluding": "29.0.2",
                "versionStartIncluding": "29.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EAB60C9A-F1B2-4377-8C9B-B8496D3D9B5C",
                "versionEndExcluding": "15.2.7.9",
                "versionStartIncluding": "6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0778AFBA-F21F-4394-AA3A-38784D379BEB",
                "versionEndExcluding": "16.4.0.2",
                "versionStartIncluding": "16.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "05F0E6B1-0DA3-4A0B-8C89-8DFC55EC7C8B",
                "versionEndExcluding": "17.0.2",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk.\n\nThe sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a single crafted SCTP ERROR chunk containing enough cause codes to overflow the stack buffer, crashing the VM. The attacker can only write 16-bit values interleaved with a fixed tag, so the overflow does not provide a controlled return address, limiting exploitation to Denial of Service.\n\nA crafted SCTP ERROR chunk may also leak bits and pieces of Erlang VM memory into the received error packet observed by the Erlang process. Such data is already readable by the user running the Erlang VM, so the disclosure scope is limited.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to erts from 6.0 before 15.2.7.9, 16.4.0.2, and 17.0.2. Whether OTP before OTP 17.0, corresponding to erts before 6.0, is affected is unknown."
      }
    ],
    "id": "CVE-2026-49759",
    "lastModified": "2026-09-24T21:17:14.810",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-49759",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-10T16:18:27.945916Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-10T16:17:12.797",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cna.erlef.org/cves/CVE-2026-49759.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/erlang/otp/commit/3983d495284331c121f600a80bac9fcf4e16381e"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/erlang/otp/security/advisories/GHSA-6f4f-chj5-5g97"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://osv.dev/vulnerability/EEF-CVE-2026-49759"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Product"
        ],
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://access.redhat.com/security/cve/CVE-2026-49759"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487607"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49759.json"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-121"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-120"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
NVDCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
receipt
Source
NVD
Its words
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.vectorString || field:cve.metrics.cvssMetricV31[].cvssData.vectorString
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "otp",
            "packageURL": "pkg:software-id/erlang.org/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "27.3.4.13",
                    "status": "unaffected"
                  },
                  {
                    "at": "28.5.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "29.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "17.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erts",
            "packageURL": "pkg:otp/erts?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
            "product": "OTP",
            "programFiles": [
              "emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "15.2.7.9",
                    "status": "unaffected"
                  },
                  {
                    "at": "16.4.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "17.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "6.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erlang/otp",
            "packageURL": "pkg:github/erlang/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "lessThan": "3983d495284331c121f600a80bac9fcf4e16381e",
                "status": "affected",
                "version": "84adefa331c4159d432d22840663c38f155cd4c1",
                "versionType": "git"
              },
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "3983d495284331c121f600a80bac9fcf4e16381e",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      },
      {
        "affectedData": [
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:16.2"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 16.2",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:17.1"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 17.1",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:18.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 18.0",
            "vendor": "Red Hat"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BF42A5F2-4C27-43FE-B5FA-17A3422B9649",
                "versionEndExcluding": "27.3.4.13",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
                "versionEndExcluding": "28.5.0.2",
                "versionStartIncluding": "28.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
                "versionEndExcluding": "29.0.2",
                "versionStartIncluding": "29.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EAB60C9A-F1B2-4377-8C9B-B8496D3D9B5C",
                "versionEndExcluding": "15.2.7.9",
                "versionStartIncluding": "6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0778AFBA-F21F-4394-AA3A-38784D379BEB",
                "versionEndExcluding": "16.4.0.2",
                "versionStartIncluding": "16.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "05F0E6B1-0DA3-4A0B-8C89-8DFC55EC7C8B",
                "versionEndExcluding": "17.0.2",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk.\n\nThe sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a single crafted SCTP ERROR chunk containing enough cause codes to overflow the stack buffer, crashing the VM. The attacker can only write 16-bit values interleaved with a fixed tag, so the overflow does not provide a controlled return address, limiting exploitation to Denial of Service.\n\nA crafted SCTP ERROR chunk may also leak bits and pieces of Erlang VM memory into the received error packet observed by the Erlang process. Such data is already readable by the user running the Erlang VM, so the disclosure scope is limited.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to erts from 6.0 before 15.2.7.9, 16.4.0.2, and 17.0.2. Whether OTP before OTP 17.0, corresponding to erts before 6.0, is affected is unknown."
      }
    ],
    "id": "CVE-2026-49759",
    "lastModified": "2026-09-24T21:17:14.810",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-49759",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-10T16:18:27.945916Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-10T16:17:12.797",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cna.erlef.org/cves/CVE-2026-49759.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/erlang/otp/commit/3983d495284331c121f600a80bac9fcf4e16381e"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/erlang/otp/security/advisories/GHSA-6f4f-chj5-5g97"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://osv.dev/vulnerability/EEF-CVE-2026-49759"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Product"
        ],
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://access.redhat.com/security/cve/CVE-2026-49759"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487607"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49759.json"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-121"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-120"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "type": "Secondary"
      }
    ]
  }
}
—
CVSS vector
cvss_vector
Red HatCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
receipt
Source
Red Hat
Its words
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Read by
field:cvss3_scoring_vector
Said since
2026-10-06 13:01 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
2026-10-06 13:01 UTCCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
2026-09-29 09:44 UTC—
What the source handed over
{
  "CVE": "CVE-2026-49759",
  "CWE": "CWE-120",
  "advisories": [
    "RHSA-2026:63160"
  ],
  "affected_packages": [
    "erlang27-main-27.3.4.17-1.hum1"
  ],
  "bugzilla": "2487607",
  "bugzilla_description": "erlang: Erlang OTP: Denial of Service via crafted SCTP ERROR chunk",
  "cvss3_score": "8.2",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-10T14:35:38Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-49759.json",
  "severity": "important"
}
—
CWE
cwe
different words
NVDCWE-121, CWE-120
receipt
Source
NVD
Its words
CWE-121, CWE-120
Read by
field:cve.weaknesses[].description[].value
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCCWE-121, CWE-120
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "otp",
            "packageURL": "pkg:software-id/erlang.org/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "27.3.4.13",
                    "status": "unaffected"
                  },
                  {
                    "at": "28.5.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "29.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "17.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erts",
            "packageURL": "pkg:otp/erts?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
            "product": "OTP",
            "programFiles": [
              "emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "15.2.7.9",
                    "status": "unaffected"
                  },
                  {
                    "at": "16.4.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "17.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "6.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erlang/otp",
            "packageURL": "pkg:github/erlang/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "lessThan": "3983d495284331c121f600a80bac9fcf4e16381e",
                "status": "affected",
                "version": "84adefa331c4159d432d22840663c38f155cd4c1",
                "versionType": "git"
              },
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "3983d495284331c121f600a80bac9fcf4e16381e",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      },
      {
        "affectedData": [
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:16.2"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 16.2",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:17.1"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 17.1",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:18.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 18.0",
            "vendor": "Red Hat"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BF42A5F2-4C27-43FE-B5FA-17A3422B9649",
                "versionEndExcluding": "27.3.4.13",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
                "versionEndExcluding": "28.5.0.2",
                "versionStartIncluding": "28.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
                "versionEndExcluding": "29.0.2",
                "versionStartIncluding": "29.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EAB60C9A-F1B2-4377-8C9B-B8496D3D9B5C",
                "versionEndExcluding": "15.2.7.9",
                "versionStartIncluding": "6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0778AFBA-F21F-4394-AA3A-38784D379BEB",
                "versionEndExcluding": "16.4.0.2",
                "versionStartIncluding": "16.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "05F0E6B1-0DA3-4A0B-8C89-8DFC55EC7C8B",
                "versionEndExcluding": "17.0.2",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk.\n\nThe sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a single crafted SCTP ERROR chunk containing enough cause codes to overflow the stack buffer, crashing the VM. The attacker can only write 16-bit values interleaved with a fixed tag, so the overflow does not provide a controlled return address, limiting exploitation to Denial of Service.\n\nA crafted SCTP ERROR chunk may also leak bits and pieces of Erlang VM memory into the received error packet observed by the Erlang process. Such data is already readable by the user running the Erlang VM, so the disclosure scope is limited.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to erts from 6.0 before 15.2.7.9, 16.4.0.2, and 17.0.2. Whether OTP before OTP 17.0, corresponding to erts before 6.0, is affected is unknown."
      }
    ],
    "id": "CVE-2026-49759",
    "lastModified": "2026-09-24T21:17:14.810",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-49759",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-10T16:18:27.945916Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-10T16:17:12.797",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cna.erlef.org/cves/CVE-2026-49759.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/erlang/otp/commit/3983d495284331c121f600a80bac9fcf4e16381e"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/erlang/otp/security/advisories/GHSA-6f4f-chj5-5g97"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://osv.dev/vulnerability/EEF-CVE-2026-49759"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Product"
        ],
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://access.redhat.com/security/cve/CVE-2026-49759"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487607"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49759.json"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-121"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-120"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "type": "Secondary"
      }
    ]
  }
}
—
CWE
cwe
different words
Red HatCWE-120
receipt
Source
Red Hat
Its words
CWE-120
Read by
field:CWE
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-49759",
  "CWE": "CWE-120",
  "advisories": [
    "RHSA-2026:63160"
  ],
  "affected_packages": [
    "erlang27-main-27.3.4.17-1.hum1"
  ],
  "bugzilla": "2487607",
  "bugzilla_description": "erlang: Erlang OTP: Denial of Service via crafted SCTP ERROR chunk",
  "cvss3_score": "8.2",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-10T14:35:38Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-49759.json",
  "severity": "important"
}
—
Exploitation
exploitation
NVDnone
No evidence of exploitation, and no public proof of concept.
receipt
Source
NVD
Its words
none
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].exploitation
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCnone
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "otp",
            "packageURL": "pkg:software-id/erlang.org/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "27.3.4.13",
                    "status": "unaffected"
                  },
                  {
                    "at": "28.5.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "29.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "17.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erts",
            "packageURL": "pkg:otp/erts?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
            "product": "OTP",
            "programFiles": [
              "emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "15.2.7.9",
                    "status": "unaffected"
                  },
                  {
                    "at": "16.4.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "17.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "6.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erlang/otp",
            "packageURL": "pkg:github/erlang/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "lessThan": "3983d495284331c121f600a80bac9fcf4e16381e",
                "status": "affected",
                "version": "84adefa331c4159d432d22840663c38f155cd4c1",
                "versionType": "git"
              },
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "3983d495284331c121f600a80bac9fcf4e16381e",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      },
      {
        "affectedData": [
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:16.2"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 16.2",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:17.1"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 17.1",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:18.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 18.0",
            "vendor": "Red Hat"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BF42A5F2-4C27-43FE-B5FA-17A3422B9649",
                "versionEndExcluding": "27.3.4.13",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
                "versionEndExcluding": "28.5.0.2",
                "versionStartIncluding": "28.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
                "versionEndExcluding": "29.0.2",
                "versionStartIncluding": "29.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EAB60C9A-F1B2-4377-8C9B-B8496D3D9B5C",
                "versionEndExcluding": "15.2.7.9",
                "versionStartIncluding": "6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0778AFBA-F21F-4394-AA3A-38784D379BEB",
                "versionEndExcluding": "16.4.0.2",
                "versionStartIncluding": "16.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "05F0E6B1-0DA3-4A0B-8C89-8DFC55EC7C8B",
                "versionEndExcluding": "17.0.2",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk.\n\nThe sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a single crafted SCTP ERROR chunk containing enough cause codes to overflow the stack buffer, crashing the VM. The attacker can only write 16-bit values interleaved with a fixed tag, so the overflow does not provide a controlled return address, limiting exploitation to Denial of Service.\n\nA crafted SCTP ERROR chunk may also leak bits and pieces of Erlang VM memory into the received error packet observed by the Erlang process. Such data is already readable by the user running the Erlang VM, so the disclosure scope is limited.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to erts from 6.0 before 15.2.7.9, 16.4.0.2, and 17.0.2. Whether OTP before OTP 17.0, corresponding to erts before 6.0, is affected is unknown."
      }
    ],
    "id": "CVE-2026-49759",
    "lastModified": "2026-09-24T21:17:14.810",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-49759",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-10T16:18:27.945916Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-10T16:17:12.797",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cna.erlef.org/cves/CVE-2026-49759.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/erlang/otp/commit/3983d495284331c121f600a80bac9fcf4e16381e"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/erlang/otp/security/advisories/GHSA-6f4f-chj5-5g97"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://osv.dev/vulnerability/EEF-CVE-2026-49759"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Product"
        ],
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://access.redhat.com/security/cve/CVE-2026-49759"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487607"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49759.json"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-121"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-120"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "type": "Secondary"
      }
    ]
  }
}
—
Packages
packages
Red Haterlang27-main-27.3.4.17-1.hum1
receipt
Source
Red Hat
Its words
erlang27-main-27.3.4.17-1.hum1
Read by
field:affected_packages[]
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-49759",
  "CWE": "CWE-120",
  "advisories": [
    "RHSA-2026:63160"
  ],
  "affected_packages": [
    "erlang27-main-27.3.4.17-1.hum1"
  ],
  "bugzilla": "2487607",
  "bugzilla_description": "erlang: Erlang OTP: Denial of Service via crafted SCTP ERROR chunk",
  "cvss3_score": "8.2",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-10T14:35:38Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-49759.json",
  "severity": "important"
}
—
Product
product
NVDOTP
receipt
Source
NVD
Its words
OTP
Read by
field:cve.affected[].affectedData[].product
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCOTP
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "otp",
            "packageURL": "pkg:software-id/erlang.org/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "27.3.4.13",
                    "status": "unaffected"
                  },
                  {
                    "at": "28.5.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "29.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "17.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erts",
            "packageURL": "pkg:otp/erts?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
            "product": "OTP",
            "programFiles": [
              "emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "15.2.7.9",
                    "status": "unaffected"
                  },
                  {
                    "at": "16.4.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "17.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "6.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erlang/otp",
            "packageURL": "pkg:github/erlang/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "lessThan": "3983d495284331c121f600a80bac9fcf4e16381e",
                "status": "affected",
                "version": "84adefa331c4159d432d22840663c38f155cd4c1",
                "versionType": "git"
              },
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "3983d495284331c121f600a80bac9fcf4e16381e",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      },
      {
        "affectedData": [
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:16.2"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 16.2",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:17.1"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 17.1",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:18.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 18.0",
            "vendor": "Red Hat"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BF42A5F2-4C27-43FE-B5FA-17A3422B9649",
                "versionEndExcluding": "27.3.4.13",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
                "versionEndExcluding": "28.5.0.2",
                "versionStartIncluding": "28.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
                "versionEndExcluding": "29.0.2",
                "versionStartIncluding": "29.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EAB60C9A-F1B2-4377-8C9B-B8496D3D9B5C",
                "versionEndExcluding": "15.2.7.9",
                "versionStartIncluding": "6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0778AFBA-F21F-4394-AA3A-38784D379BEB",
                "versionEndExcluding": "16.4.0.2",
                "versionStartIncluding": "16.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "05F0E6B1-0DA3-4A0B-8C89-8DFC55EC7C8B",
                "versionEndExcluding": "17.0.2",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk.\n\nThe sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a single crafted SCTP ERROR chunk containing enough cause codes to overflow the stack buffer, crashing the VM. The attacker can only write 16-bit values interleaved with a fixed tag, so the overflow does not provide a controlled return address, limiting exploitation to Denial of Service.\n\nA crafted SCTP ERROR chunk may also leak bits and pieces of Erlang VM memory into the received error packet observed by the Erlang process. Such data is already readable by the user running the Erlang VM, so the disclosure scope is limited.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to erts from 6.0 before 15.2.7.9, 16.4.0.2, and 17.0.2. Whether OTP before OTP 17.0, corresponding to erts before 6.0, is affected is unknown."
      }
    ],
    "id": "CVE-2026-49759",
    "lastModified": "2026-09-24T21:17:14.810",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-49759",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-10T16:18:27.945916Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-10T16:17:12.797",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cna.erlef.org/cves/CVE-2026-49759.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/erlang/otp/commit/3983d495284331c121f600a80bac9fcf4e16381e"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/erlang/otp/security/advisories/GHSA-6f4f-chj5-5g97"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://osv.dev/vulnerability/EEF-CVE-2026-49759"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Product"
        ],
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://access.redhat.com/security/cve/CVE-2026-49759"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487607"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49759.json"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-121"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-120"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "type": "Secondary"
      }
    ]
  }
}
—
Severity
severity
NVDHIGH
From 7.0 to 8.9.
receipt
Source
NVD
Its words
HIGH
Read by
field:cve.metrics.cvssMetricV31[type=Primary].cvssData.baseSeverity || field:cve.metrics.cvssMetricV31[].cvssData.baseSeverity
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCHIGH
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "otp",
            "packageURL": "pkg:software-id/erlang.org/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "27.3.4.13",
                    "status": "unaffected"
                  },
                  {
                    "at": "28.5.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "29.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "17.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erts",
            "packageURL": "pkg:otp/erts?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
            "product": "OTP",
            "programFiles": [
              "emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "15.2.7.9",
                    "status": "unaffected"
                  },
                  {
                    "at": "16.4.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "17.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "6.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erlang/otp",
            "packageURL": "pkg:github/erlang/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "lessThan": "3983d495284331c121f600a80bac9fcf4e16381e",
                "status": "affected",
                "version": "84adefa331c4159d432d22840663c38f155cd4c1",
                "versionType": "git"
              },
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "3983d495284331c121f600a80bac9fcf4e16381e",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      },
      {
        "affectedData": [
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:16.2"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 16.2",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:17.1"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 17.1",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:18.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 18.0",
            "vendor": "Red Hat"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BF42A5F2-4C27-43FE-B5FA-17A3422B9649",
                "versionEndExcluding": "27.3.4.13",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
                "versionEndExcluding": "28.5.0.2",
                "versionStartIncluding": "28.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
                "versionEndExcluding": "29.0.2",
                "versionStartIncluding": "29.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EAB60C9A-F1B2-4377-8C9B-B8496D3D9B5C",
                "versionEndExcluding": "15.2.7.9",
                "versionStartIncluding": "6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0778AFBA-F21F-4394-AA3A-38784D379BEB",
                "versionEndExcluding": "16.4.0.2",
                "versionStartIncluding": "16.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "05F0E6B1-0DA3-4A0B-8C89-8DFC55EC7C8B",
                "versionEndExcluding": "17.0.2",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk.\n\nThe sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a single crafted SCTP ERROR chunk containing enough cause codes to overflow the stack buffer, crashing the VM. The attacker can only write 16-bit values interleaved with a fixed tag, so the overflow does not provide a controlled return address, limiting exploitation to Denial of Service.\n\nA crafted SCTP ERROR chunk may also leak bits and pieces of Erlang VM memory into the received error packet observed by the Erlang process. Such data is already readable by the user running the Erlang VM, so the disclosure scope is limited.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to erts from 6.0 before 15.2.7.9, 16.4.0.2, and 17.0.2. Whether OTP before OTP 17.0, corresponding to erts before 6.0, is affected is unknown."
      }
    ],
    "id": "CVE-2026-49759",
    "lastModified": "2026-09-24T21:17:14.810",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-49759",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-10T16:18:27.945916Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-10T16:17:12.797",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cna.erlef.org/cves/CVE-2026-49759.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/erlang/otp/commit/3983d495284331c121f600a80bac9fcf4e16381e"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/erlang/otp/security/advisories/GHSA-6f4f-chj5-5g97"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://osv.dev/vulnerability/EEF-CVE-2026-49759"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Product"
        ],
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://access.redhat.com/security/cve/CVE-2026-49759"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487607"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49759.json"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-121"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-120"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "type": "Secondary"
      }
    ]
  }
}
high
Severity
severity
Red Hatimportant
A flaw that can easily compromise confidentiality, integrity or availability.
receipt
Source
Red Hat
Its words
important
Read by
field:severity
Said since
2026-09-29 09:44 UTC
Last answered
2026-10-06 13:02 UTC
Original
open at the source
What the source handed over
{
  "CVE": "CVE-2026-49759",
  "CWE": "CWE-120",
  "advisories": [
    "RHSA-2026:63160"
  ],
  "affected_packages": [
    "erlang27-main-27.3.4.17-1.hum1"
  ],
  "bugzilla": "2487607",
  "bugzilla_description": "erlang: Erlang OTP: Denial of Service via crafted SCTP ERROR chunk",
  "cvss3_score": "8.2",
  "cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
  "cvss_score": null,
  "cvss_scoring_vector": null,
  "package_state": null,
  "public_date": "2026-06-10T14:35:38Z",
  "resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2026-49759.json",
  "severity": "important"
}
high
Status
status
NVDModified
receipt
Source
NVD
Its words
Modified
Read by
field:cve.vulnStatus
Said since
2026-09-29 09:45 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "otp",
            "packageURL": "pkg:software-id/erlang.org/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "27.3.4.13",
                    "status": "unaffected"
                  },
                  {
                    "at": "28.5.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "29.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "17.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erts",
            "packageURL": "pkg:otp/erts?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
            "product": "OTP",
            "programFiles": [
              "emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "15.2.7.9",
                    "status": "unaffected"
                  },
                  {
                    "at": "16.4.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "17.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "6.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erlang/otp",
            "packageURL": "pkg:github/erlang/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "lessThan": "3983d495284331c121f600a80bac9fcf4e16381e",
                "status": "affected",
                "version": "84adefa331c4159d432d22840663c38f155cd4c1",
                "versionType": "git"
              },
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "3983d495284331c121f600a80bac9fcf4e16381e",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      },
      {
        "affectedData": [
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:16.2"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 16.2",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:17.1"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 17.1",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:18.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 18.0",
            "vendor": "Red Hat"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BF42A5F2-4C27-43FE-B5FA-17A3422B9649",
                "versionEndExcluding": "27.3.4.13",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
                "versionEndExcluding": "28.5.0.2",
                "versionStartIncluding": "28.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
                "versionEndExcluding": "29.0.2",
                "versionStartIncluding": "29.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EAB60C9A-F1B2-4377-8C9B-B8496D3D9B5C",
                "versionEndExcluding": "15.2.7.9",
                "versionStartIncluding": "6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0778AFBA-F21F-4394-AA3A-38784D379BEB",
                "versionEndExcluding": "16.4.0.2",
                "versionStartIncluding": "16.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "05F0E6B1-0DA3-4A0B-8C89-8DFC55EC7C8B",
                "versionEndExcluding": "17.0.2",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk.\n\nThe sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a single crafted SCTP ERROR chunk containing enough cause codes to overflow the stack buffer, crashing the VM. The attacker can only write 16-bit values interleaved with a fixed tag, so the overflow does not provide a controlled return address, limiting exploitation to Denial of Service.\n\nA crafted SCTP ERROR chunk may also leak bits and pieces of Erlang VM memory into the received error packet observed by the Erlang process. Such data is already readable by the user running the Erlang VM, so the disclosure scope is limited.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to erts from 6.0 before 15.2.7.9, 16.4.0.2, and 17.0.2. Whether OTP before OTP 17.0, corresponding to erts before 6.0, is affected is unknown."
      }
    ],
    "id": "CVE-2026-49759",
    "lastModified": "2026-09-24T21:17:14.810",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-49759",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-10T16:18:27.945916Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-10T16:17:12.797",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cna.erlef.org/cves/CVE-2026-49759.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/erlang/otp/commit/3983d495284331c121f600a80bac9fcf4e16381e"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/erlang/otp/security/advisories/GHSA-6f4f-chj5-5g97"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://osv.dev/vulnerability/EEF-CVE-2026-49759"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Product"
        ],
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://access.redhat.com/security/cve/CVE-2026-49759"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487607"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49759.json"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-121"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-120"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "type": "Secondary"
      }
    ]
  }
}
—
Technical impact
technical_impact
NVDpartial
The attacker gains limited control, or limited information.
receipt
Source
NVD
Its words
partial
Read by
field:cve.metrics.ssvcV203[].ssvcData.options[].technicalImpact
Said since
2026-10-06 12:29 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-10-06 12:29 UTCpartial
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "otp",
            "packageURL": "pkg:software-id/erlang.org/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "27.3.4.13",
                    "status": "unaffected"
                  },
                  {
                    "at": "28.5.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "29.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "17.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erts",
            "packageURL": "pkg:otp/erts?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
            "product": "OTP",
            "programFiles": [
              "emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "15.2.7.9",
                    "status": "unaffected"
                  },
                  {
                    "at": "16.4.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "17.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "6.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erlang/otp",
            "packageURL": "pkg:github/erlang/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "lessThan": "3983d495284331c121f600a80bac9fcf4e16381e",
                "status": "affected",
                "version": "84adefa331c4159d432d22840663c38f155cd4c1",
                "versionType": "git"
              },
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "3983d495284331c121f600a80bac9fcf4e16381e",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      },
      {
        "affectedData": [
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:16.2"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 16.2",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:17.1"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 17.1",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:18.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 18.0",
            "vendor": "Red Hat"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BF42A5F2-4C27-43FE-B5FA-17A3422B9649",
                "versionEndExcluding": "27.3.4.13",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
                "versionEndExcluding": "28.5.0.2",
                "versionStartIncluding": "28.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
                "versionEndExcluding": "29.0.2",
                "versionStartIncluding": "29.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EAB60C9A-F1B2-4377-8C9B-B8496D3D9B5C",
                "versionEndExcluding": "15.2.7.9",
                "versionStartIncluding": "6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0778AFBA-F21F-4394-AA3A-38784D379BEB",
                "versionEndExcluding": "16.4.0.2",
                "versionStartIncluding": "16.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "05F0E6B1-0DA3-4A0B-8C89-8DFC55EC7C8B",
                "versionEndExcluding": "17.0.2",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk.\n\nThe sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a single crafted SCTP ERROR chunk containing enough cause codes to overflow the stack buffer, crashing the VM. The attacker can only write 16-bit values interleaved with a fixed tag, so the overflow does not provide a controlled return address, limiting exploitation to Denial of Service.\n\nA crafted SCTP ERROR chunk may also leak bits and pieces of Erlang VM memory into the received error packet observed by the Erlang process. Such data is already readable by the user running the Erlang VM, so the disclosure scope is limited.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to erts from 6.0 before 15.2.7.9, 16.4.0.2, and 17.0.2. Whether OTP before OTP 17.0, corresponding to erts before 6.0, is affected is unknown."
      }
    ],
    "id": "CVE-2026-49759",
    "lastModified": "2026-09-24T21:17:14.810",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-49759",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-10T16:18:27.945916Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-10T16:17:12.797",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cna.erlef.org/cves/CVE-2026-49759.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/erlang/otp/commit/3983d495284331c121f600a80bac9fcf4e16381e"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/erlang/otp/security/advisories/GHSA-6f4f-chj5-5g97"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://osv.dev/vulnerability/EEF-CVE-2026-49759"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Product"
        ],
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://access.redhat.com/security/cve/CVE-2026-49759"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487607"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49759.json"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-121"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-120"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "type": "Secondary"
      }
    ]
  }
}
—
Vendor
vendor
NVDErlang
receipt
Source
NVD
Its words
Erlang
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-09-29 17:49 UTC
Last answered
2026-10-06 12:41 UTC
Original
open at the source
2026-09-29 17:49 UTCErlang
2026-09-29 09:45 UTC—
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "otp",
            "packageURL": "pkg:software-id/erlang.org/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "27.3.4.13",
                    "status": "unaffected"
                  },
                  {
                    "at": "28.5.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "29.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "17.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erts",
            "packageURL": "pkg:otp/erts?repository_url=https:%2F%2Fgithub.com%2Ferlang%2Fotp&vcs_url=git%2Bhttps:%2F%2Fgithub.com%2Ferlang%2Fotp.git",
            "product": "OTP",
            "programFiles": [
              "emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "changes": [
                  {
                    "at": "15.2.7.9",
                    "status": "unaffected"
                  },
                  {
                    "at": "16.4.0.2",
                    "status": "unaffected"
                  },
                  {
                    "at": "17.0.2",
                    "status": "unaffected"
                  }
                ],
                "lessThan": "*",
                "status": "affected",
                "version": "6.0",
                "versionType": "otp"
              }
            ]
          },
          {
            "collectionURL": "https://github.com",
            "cpes": [
              "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
            ],
            "defaultStatus": "unknown",
            "modules": [
              "inet_drv"
            ],
            "packageName": "erlang/otp",
            "packageURL": "pkg:github/erlang/otp",
            "product": "OTP",
            "programFiles": [
              "erts/emulator/drivers/common/inet_drv.c"
            ],
            "programRoutines": [
              {
                "name": "sctp_parse_error_chunk"
              }
            ],
            "repo": "https://github.com/erlang/otp",
            "vendor": "Erlang",
            "versions": [
              {
                "lessThan": "3983d495284331c121f600a80bac9fcf4e16381e",
                "status": "affected",
                "version": "84adefa331c4159d432d22840663c38f155cd4c1",
                "versionType": "git"
              },
              {
                "lessThan": "*",
                "status": "unaffected",
                "version": "3983d495284331c121f600a80bac9fcf4e16381e",
                "versionType": "git"
              }
            ]
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db"
      },
      {
        "affectedData": [
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:16.2"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 16.2",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:17.1"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 17.1",
            "vendor": "Red Hat"
          },
          {
            "collectionURL": "https://access.redhat.com/downloads/content/package-browser/",
            "cpes": [
              "cpe:/a:redhat:openstack:18.0"
            ],
            "defaultStatus": "unaffected",
            "packageName": "erlang",
            "product": "Red Hat OpenStack Platform 18.0",
            "vendor": "Red Hat"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "BF42A5F2-4C27-43FE-B5FA-17A3422B9649",
                "versionEndExcluding": "27.3.4.13",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "902ED4C3-B9DE-4ABC-9BEA-D23DA4F5D373",
                "versionEndExcluding": "28.5.0.2",
                "versionStartIncluding": "28.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "F4AB1573-4E81-4338-B65A-B3C94C7249FA",
                "versionEndExcluding": "29.0.2",
                "versionStartIncluding": "29.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "EAB60C9A-F1B2-4377-8C9B-B8496D3D9B5C",
                "versionEndExcluding": "15.2.7.9",
                "versionStartIncluding": "6.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "0778AFBA-F21F-4394-AA3A-38784D379BEB",
                "versionEndExcluding": "16.4.0.2",
                "versionStartIncluding": "16.0",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:a:erlang:erts:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "05F0E6B1-0DA3-4A0B-8C89-8DFC55EC7C8B",
                "versionEndExcluding": "17.0.2",
                "versionStartIncluding": "17.0",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk.\n\nThe sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a single crafted SCTP ERROR chunk containing enough cause codes to overflow the stack buffer, crashing the VM. The attacker can only write 16-bit values interleaved with a fixed tag, so the overflow does not provide a controlled return address, limiting exploitation to Denial of Service.\n\nA crafted SCTP ERROR chunk may also leak bits and pieces of Erlang VM memory into the received error packet observed by the Erlang process. Such data is already readable by the user running the Erlang VM, so the disclosure scope is limited.\n\nThis issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to erts from 6.0 before 15.2.7.9, 16.4.0.2, and 17.0.2. Whether OTP before OTP 17.0, corresponding to erts before 6.0, is affected is unknown."
      }
    ],
    "id": "CVE-2026-49759",
    "lastModified": "2026-09-24T21:17:14.810",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "nvd@nist.gov",
          "type": "Primary"
        },
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.2,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 3.9,
          "impactScore": 4.2,
          "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
          "type": "Secondary"
        }
      ],
      "cvssMetricV40": [
        {
          "cvssData": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "availabilityRequirement": "NOT_DEFINED",
            "baseScore": 8.8,
            "baseSeverity": "HIGH",
            "confidentialityRequirement": "NOT_DEFINED",
            "exploitMaturity": "NOT_DEFINED",
            "integrityRequirement": "NOT_DEFINED",
            "modifiedAttackComplexity": "NOT_DEFINED",
            "modifiedAttackRequirements": "NOT_DEFINED",
            "modifiedAttackVector": "NOT_DEFINED",
            "modifiedPrivilegesRequired": "NOT_DEFINED",
            "modifiedSubAvailabilityImpact": "NOT_DEFINED",
            "modifiedSubConfidentialityImpact": "NOT_DEFINED",
            "modifiedSubIntegrityImpact": "NOT_DEFINED",
            "modifiedUserInteraction": "NOT_DEFINED",
            "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
            "modifiedVulnConfidentialityImpact": "NOT_DEFINED",
            "modifiedVulnIntegrityImpact": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "LOW",
            "vulnIntegrityImpact": "NONE",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-49759",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "yes"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-06-10T16:18:27.945916Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-06-10T16:17:12.797",
    "references": [
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://cna.erlef.org/cves/CVE-2026-49759.html"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/erlang/otp/commit/3983d495284331c121f600a80bac9fcf4e16381e"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://github.com/erlang/otp/security/advisories/GHSA-6f4f-chj5-5g97"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Third Party Advisory"
        ],
        "url": "https://osv.dev/vulnerability/EEF-CVE-2026-49759"
      },
      {
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "tags": [
          "Product"
        ],
        "url": "https://www.erlang.org/doc/system/versions.html#order-of-versions"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://access.redhat.com/security/cve/CVE-2026-49759"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2487607"
      },
      {
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49759.json"
      }
    ],
    "sourceIdentifier": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
    "vulnStatus": "Modified",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-121"
          }
        ],
        "source": "6b3ad84c-e1a6-4bf7-a703-f496b71e49db",
        "type": "Secondary"
      },
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-120"
          }
        ],
        "source": "0b0ca135-0b70-47e7-9f44-1890c2a1c46c",
        "type": "Secondary"
      }
    ]
  }
}
—
Every claim, by kind

vulnerability

erlang: Erlang OTP: Denial of Service via crafted SCTP ERROR chunk
zetlyn/cve-redhat · 2026-06-10
cvss 8.2 cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H cwe CWE-120 packages erlang27-main-27.3.4.17-1.hum1 severity important source
Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk. The sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a single crafted SCTP ERROR chunk containing enough cause codes to overflow the stack buffer, crashing the VM. The attacker can only write 16-bit values interleaved with a fixed tag, so the overflow does not provide a controlled return address, limiting exploitation to Denial of Service. A crafted SCTP ERROR chunk may also leak bits and pieces of Erlang VM memory into the received error packet observed by the Erlang process. Such data is already readable by the user running the Erlang VM, so the disclosure scope is limited. This issue affects OTP from OTP 17.0 before OTP 27.3.4.13, OTP 28.5.0.2, and OTP 29.0.2, corresponding to erts from 6.0 before 15.2.7.9, 16.4.0.2, and 17.0.2. Whether OTP before OTP 17.0, corresponding to erts before 6.0, is affected is unknown.
zetlyn/cve-nvd · 2026-06-10
automatable yes cvss 8.2 cvss4 8.8 cvss4_vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X cvss_vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H cwe CWE-121, CWE-120 exploitation none product OTP severity HIGH status Modified technical_impact partial vendor Erlang source