{"id":"CVE-2026-49759","title":"erlang: Erlang OTP: Denial of Service via crafted SCTP ERROR chunk (CVE-2026-49759)","summary":"A flaw was found in Erlang OTP (Open Telecom Platform) erts, specifically within the `inet_drv` component. An unauthenticated remote attacker can exploit a stack-based buffer overflow vulnerability by sending a specially crafted Stream Con…","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H","cvssSource":"vendor","cwe":["CWE-120","CWE-121"],"vendor":"Red Hat","product":"Red Hat Hardened Images","affected":["hardened_images"],"patched":["hardened_images"],"published":"2026-06-10","updated":"2026-09-21","sourceUpdated":"2026-09-21T10:36:47+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49759.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-49759.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-49759"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2487607"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-49759"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49759"},{"url":"https://cna.erlef.org/cves/CVE-2026-49759.html"},{"url":"https://github.com/erlang/otp/commit/3983d495284331c121f600a80bac9fcf4e16381e"},{"url":"https://github.com/erlang/otp/security/advisories/GHSA-6f4f-chj5-5g97"},{"url":"https://osv.dev/vulnerability/EEF-CVE-2026-49759"},{"url":"https://www.erlang.org/doc/system/versions.html#order-of-versions"},{"url":"https://access.redhat.com/errata/RHSA-2026:63160"}],"tags":["csaf","vex","red-hat","cve.org"],"epss":0.00497,"epssPercentile":0.41537,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-06-10T16:18:27.945916Z"},"scores":{"vendor":8.2,"cna":8.8},"ingestedAt":"2026-09-17T12:16:56.796Z","slug":"CVE-2026-49759","body":"## Overview\n\nA flaw was found in Erlang OTP (Open Telecom Platform) erts, specifically within the `inet_drv` component. An unauthenticated remote attacker can exploit a stack-based buffer overflow vulnerability by sending a specially crafted Stream Control Transmission Protocol (SCTP) ERROR chunk. This can lead to a Denial of Service (DoS) by crashing the BEAM virtual machine. Additionally, this flaw may result in limited information disclosure by leaking small portions of Erlang VM memory.\n\n## Vendor advisories\n\n- **RHSA-2026:63160** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-09-03 · [advisory](https://access.redhat.com/errata/RHSA-2026:63160)\n\n**erlang: Erlang OTP: Denial of Service via crafted SCTP ERROR chunk** — rated Important by Red Hat. Released 2026-06-10, updated 2026-09-21.\n\nFixed:\n\n- Red Hat Hardened Images\n\nNot affected:\n\n- Red Hat OpenStack Platform 16.2\n- Red Hat OpenStack Platform 17.1\n- Red Hat OpenStack Platform 18.0\n\n## Remediation\n\nFor details on how to apply this update, which includes the changes described in this advisory, refer to:\nhttps://images.redhat.com/ https://access.redhat.com/errata/RHSA-2026:63160\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":45.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":208482,"id":"CVE-2026-49759","ts":1790005716024,"field":"cvss","old":"8.8","new":"8.2"}]}