Erlang OTP是瑞典Erlang社区的一套构建分布式系统的中间件平台。 Erlang OTP 29.0.4之前版本存在缓冲区错误漏洞,该漏洞源于megaco flex scanner C driver存在经典缓冲区溢出,具体是由于mfs_load_property_groups函数在处理Local/Remote描述符时,使用未检查的sprintf调用将超长属性参数名写入固定512字节的error_msg字段,导致溢出并覆盖相邻结构字段,产生任意写和任意释放原语,可能被利用实现远程代码执行或拒绝服务(
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Erlang | OTP | 17.0 ~ 27.3.4.15 |
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
|
|
| Erlang | OTP | 3.17.1 ~ 4.7.2.2 |
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
|
|
| Erlang | OTP | 84adefa331c4159d432d22840663c38f155cd4c1 ~ 8704c8f550a11ed5f825e3c011ecb03565b79c4f |
cpe:2.3:a:erlang:erlang\/otp:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55953 | 9.1 CRITICAL | TLS 1.2 and DTLS client accepts unoffered anonymous cipher suite, bypassing server authent |
| CVE-2026-58227 | 8.7 HIGH | TLS/DTLS denial of service via unbounded recursion on cross-signed peer certificate chain |
| CVE-2026-59251 | 8.7 HIGH | Denial of service via exponential certificate policy tree growth in path validation |
| CVE-2026-54890 | 8.2 HIGH | BEAM VM crash via integer underflow in binary_to_term BIT_BINARY_EXT decoding |
| CVE-2026-42792 | 6.3 MEDIUM | epmd permanent DoS via EMFILE on accept(2) in erts |
| CVE-2026-55737 | 5.1 MEDIUM | Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts e |
| CVE-2026-47078 | 4.8 MEDIUM | Relative path traversal in zip:unzip/zip:extract via check_dir_level depth-counter bypass |
No comments yet