Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-59250— Megaco flex scanner buffer overflow via oversized property parm name

Quick assessment

Affected
Erlang OTP
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Erlang OTP是瑞典Erlang社区的一套构建分布式系统的中间件平台。 Erlang OTP 29.0.4之前版本存在缓冲区错误漏洞,该漏洞源于megaco flex scanner C driver存在经典缓冲区溢出,具体是由于mfs_load_property_groups函数在处理Local/Remote描述符时,使用未检查的sprintf调用将超长属性参数名写入固定512字节的error_msg字段,导致溢出并覆盖相邻结构字段,产生任意写和任意释放原语,可能被利用实现远程代码执行或拒绝服务(

CVSS 8.3 · High EPSS 0.78% · P55

Affected Version Matrix 9

VendorProduct Version RangeStatus
Erlang OTP < 17.0 unknown
17.0< 27.3.4.15 affected
28.0< 28.5.0.4 affected
29.0< 29.0.4 affected
< 3.17.1 unknown
3.17.1< 4.7.2.2 affected
4.8< 4.8.3.1 affected
4.9< 4.9.1 affected
… +1 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-59250

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Megaco flex scanner buffer overflow via oversized property parm name
Source: CVE Program / CVE List V5
Vulnerability Description
Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and potentially achieve remote code execution or a denial-of-service crash) by sending a single text-encoded H.248/Megaco message containing an oversized property parm name. When tokenizing a Local/Remote descriptor, mfs_load_property_groups extracts the attacker-controlled property name (bounded only by the message length) and, when no value follows, formats it into a fixed 512-byte error_msg field of the MfsErlDrvData struct using an unchecked sprintf call. Names longer than roughly 452 bytes overflow into the immediately following struct fields (text_buf, text_ptr, term_spec, term_spec_size, term_spec_index), overwriting live pointers and counters with attacker-chosen bytes. Subsequent scanner code writes and frees through the corrupted pointers, producing arbitrary write and arbitrary free primitives inside the BEAM VM process, which can be leveraged for remote code execution. On builds compiled with _FORTIFY_SOURCE the overflow is detected at runtime and terminates the process with SIGABRT, resulting in denial of service. The overflow occurs in the flex scanner before any grammar or Megaco-level authentication processing, so exploitation requires only network reachability to the megaco transport port on a node configured with {scanner, flex}. This vulnerability is associated with program files lib/megaco/src/flex/megaco_flex_scanner_drv.flex.src and program routines mfs_load_property_groups. This issue affects OTP from OTP 17.0 before OTP 27.3.4.15, from OTP 28.0 before OTP 28.5.0.4, and from OTP 29.0 before OTP 29.0.4, corresponding to megaco from 3.17.1 before 4.7.2.2, from 4.8 before 4.8.3.1, and from 4.9 before 4.9.1. Whether OTP before OTP 17.0, corresponding to megaco before 3.17.1, is affected is unknown.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)
Source: CVE Program / CVE List V5
Vulnerability Title
Erlang OTP 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Erlang OTP是瑞典Erlang社区的一套构建分布式系统的中间件平台。 Erlang OTP 29.0.4之前版本存在缓冲区错误漏洞,该漏洞源于megaco flex scanner C driver存在经典缓冲区溢出,具体是由于mfs_load_property_groups函数在处理Local/Remote描述符时,使用未检查的sprintf调用将超长属性参数名写入固定512字节的error_msg字段,导致溢出并覆盖相邻结构字段,产生任意写和任意释放原语,可能被利用实现远程代码执行或拒绝服务(
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Erlang OTP 17.0 ~ 27.3.4.15 cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
Erlang OTP 3.17.1 ~ 4.7.2.2 cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
Erlang OTP 84adefa331c4159d432d22840663c38f155cd4c1 ~ 8704c8f550a11ed5f825e3c011ecb03565b79c4f cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-59250

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-59250

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-59250 (1)

Vendor Advisories for CVE-2026-59250 (3)

Same Patch Batch · Erlang · 2026-07-27 · 8 CVEs total

CVE-2026-55953 9.1 CRITICAL TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authent
CVE-2026-58227 8.7 HIGH TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain
CVE-2026-59251 8.7 HIGH Denial of service via exponential certificate policy tree growth in path validation
CVE-2026-54890 8.2 HIGH BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding
CVE-2026-42792 6.3 MEDIUM epmd permanent DoS via EMFILE on accept(2) in erts
CVE-2026-55737 5.1 MEDIUM Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts e
CVE-2026-47078 4.8 MEDIUM Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass

IV. Related Vulnerabilities

V. Comments for CVE-2026-59250

No comments yet


Leave a comment