Review reviewHigh

CVE-2026-49759

Erlang OTP, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1

Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk. The sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a single crafted SCTP ERROR chunk containing enough cause codes to overflow the stack buffer, crashing the VM. The attacke...

CVSS
8.8
EPSS
0.50%
39.9% percentile
CISA KEV
Not listed
Published
2026.06.11
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability0.50%
Technical severityCVSS 8.8

Vulnerability overview

Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk. The sctp_parse_error_chunk function in erts/emulator/drivers/common/inet_drv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a single crafted SCTP ERROR chunk containing enough cause codes to overflow the stack buffer, crashing the VM. The attacke...

Affected product and versions

Product
Erlang OTP, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1
Affected versions
>= 6.0, >= 17.0, >= 84adefa331c4159d432d22840663c38f155cd4c1 < 3983d495284331c121f600a80bac9fcf4e16381e, >= 17.0 < 27.3.4.13, >= 28.0 < 28.5.0.2, >= 29.0 < 29.0.2, >= 6.0 < 15.2.7.9, >= 16.0 < 16.4.0.2, >= 17.0 < 17.0.2
Fixed versions
27.3.4.13, 28.5.0.2, 29.0.2, 15.2.7.9, 16.4.0.2, 17.0.2

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Erlang OTP, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1 and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE
CWE-120, CWE-121
CVE-2026-49759 — Erlang OTP, Red Hat OpenStack Platform 16.2, Red Hat OpenStack Platform 17.1 | SECUFOCUS NOW