<Vulnerability name="CVE-2026-55737">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Important</ThreatSeverity>
    <PublicDate>2026-07-27T15:13:54</PublicDate>
    <Bugzilla id="2507544" url="https://bugzilla.redhat.com/show_bug.cgi?id=2507544" xml:lang="en:us">
erlang-otp: Erlang OTP: Denial of Service via crafted external term format binary
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>7.5</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-787</CWE>
    <Details xml:lang="en:us" source="Mitre">
Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can supply a crafted Erlang external term format (ETF) binary to binary_to_term/1 to corrupt the BEAM heap pointer and crash the virtual machine.

When decoding a LARGE_TUPLE_EXT term, the validation pass decoded_size() in erts/emulator/beam/external.c reads the 32-bit arity field as unsigned (get_uint32()), while the decode pass dec_term() reads the same field as a signed 32-bit integer (get_int32()) into an int. An arity wire value of 0x80000000 passes validation as 2147483648 but decodes as -2147483648, so the subsequent hp += n moves the heap allocation pointer backward. Neither pass enforces the runtime tuple-arity limit MAX_ARITYVAL. The result is an out-of-bounds heap write; in practice the VM detects an impossible heap size and aborts, denying service. The required padding is large when uncompressed but the compressed-ETF envelope shrinks it to a small payload on the wire.

This issue affects OTP from OTP 25.0 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15, corresponding to erts from 13.0 before 17.0.4, 16.4.0.4 and 15.2.7.11.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in Erlang OTP. A remote attacker can exploit a vulnerability in the Erlang external term format (ETF) decoder by providing a specially crafted binary to the binary_to_term/1 function. This manipulation of data types during processing can corrupt the system's memory, leading to an out-of-bounds write. The ultimate consequence is a denial of service (DoS), causing the Erlang virtual machine to crash.
    </Details>
    <PackageState cpe="cpe:/a:redhat:hummingbird:1">
        <ProductName>Red Hat Hardened Images</ProductName>
        <FixState>Not affected</FixState>
        <PackageName>erlang27</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-55737
https://nvd.nist.gov/vuln/detail/CVE-2026-55737
https://cna.erlef.org/cves/CVE-2026-55737.html
https://github.com/erlang/otp/commit/c5210b42a9d3d96f3d25601942ce8122be0f3761
https://github.com/erlang/otp/security/advisories/GHSA-446w-268v-9462
https://osv.dev/vulnerability/EEF-CVE-2026-55737
https://www.erlang.org/doc/system/versions.html#order-of-versions
    </References>
</Vulnerability>