REDHAT-BUG-2487607: Buffer Overflow

Published Jun 10, 2026
·
Updated

Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inetdrv) allows an unauthenticated remote attacker to crash the BEAM VM by sending a crafted SCTP ERROR chunk.

The sctpparseerrorchunk function in erts/emulator/drivers/common/inetdrv.c parses SCTP ERROR chunks and writes cause codes into a fixed-size stack-allocated ErlDrvTermData spec[] array without checking bounds. A remote attacker who has established an SCTP association to a listening port can send a single crafted SCTP ERROR chunk containing enough cause codes to overflow the stack buffer, crashing the VM. The attacker can only write 16-bit values interleaved with a fixed tag, so the overflow does not provide a controlled return address, limiting exploitation to Denial of Service.

A crafted SCTP ERROR chunk may also leak bits and pieces of Erlang VM memory into the received error packet observed by the Erlang process. Such data is already readable by the user running the Erlang VM, so the disclosure scope is limited.

This issue affects OTP from OTP 17.0 before 27.3.4.13, 28.5.0.2 and 29.0.2, corresponding to erts from 6.0 before 15.2.7.9, 16.4.0.2 and 17.0.2.

Affected Software

2 affected components
Erlang OTP>17.0<=27.3.4.13, =28.5.0.2, =29.0.2
erts<15.2.7.9, =16.4.0.2, =17.0.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Erlang OTP (erts/inet_drv) to a version that resolves this vulnerability.

    Fixed in 27.3.4.13
  2. Upgrade

    Upgrade Erlang OTP (erts/inet_drv) to a version that resolves this vulnerability.

    Fixed in 28.5.0.2
  3. Upgrade

    Upgrade Erlang OTP (erts/inet_drv) to a version that resolves this vulnerability.

    Fixed in 29.0.2
  4. Upgrade

    Upgrade Erlang erts (inet_drv) to a version that resolves this vulnerability.

    Fixed in 15.2.7.9
  5. Upgrade

    Upgrade Erlang erts (inet_drv) to a version that resolves this vulnerability.

    Fixed in 16.4.0.2
  6. Upgrade

    Upgrade Erlang erts (inet_drv) to a version that resolves this vulnerability.

    Fixed in 17.0.2

Event History

Jun 10, 2026
Data Sourced
via Red Hat·04:02 PM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2487607?

The severity of REDHAT-BUG-2487607 is classified as high with a score of 7.

2

How do I fix REDHAT-BUG-2487607?

To fix REDHAT-BUG-2487607, update to the latest version of Erlang OTP which contains the necessary patches.

3

What systems are affected by REDHAT-BUG-2487607?

Erlang OTP erts systems are affected by REDHAT-BUG-2487607, particularly those utilizing the inet_drv.

4

What type of vulnerability is REDHAT-BUG-2487607?

REDHAT-BUG-2487607 is a stack-based buffer overflow vulnerability.

5

Can REDHAT-BUG-2487607 be exploited remotely?

Yes, REDHAT-BUG-2487607 can be exploited by an unauthenticated remote attacker.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203