Erlang/OTP disclosed CVE-2026-49759, a high-severity stack buffer overflow in the inet_drv SCTP error-cause parsing path that can let an unauthenticated remote attacker crash the BEAM VM. The flaw is in sctp_parse_error_chunk in erts/emulator/drivers/common/inet_drv.c, where crafted SCTP ERROR chunks can overflow a fixed-size stack buffer while cause codes are converted into ErlDrvTermData entries. Exploitation requires SCTP support to be enabled, a listening SCTP socket to be exposed through gen_sctp using the default inet backend, and network reachability to that port; Windows builds are not affected because SCTP is unsupported there.
Advisories and the upstream patch indicate the issue is primarily denial of service, not expected remote code execution, because stack protections should terminate the process before meaningful control of execution is possible and the overwrite pattern is constrained. A crafted packet may also leak limited Erlang VM memory in an error response. The vulnerability affects OTP releases from 17.0 up to but excluding 27.3.4.13, 28.5.0.2, and 29.0.2. The fix adds bounds checking and truncation safeguards in SCTP parsing and related async-event handling to prevent output term buffer overruns during malformed packet processing.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
A CNA record was published for CVE-2026-49759 describing a stack buffer overflow in SCTP error cause parsing in inet_drv that allows a remote VM crash.
On 2026-06-10, Erlang published security advisories covering multiple vulnerabilities across OTP and related components, including the SCTP inet_drv overflow, a Distribution-over-TLS LAN allowlist bypass, and an httpc flaw that can leak Authorization headers on cross-origin redirects. The notice identified affected and fixed versions for OTP, erts, inets, and ssl, and urged administrators to apply updates.
OSV and CVE feed entries published vulnerability details and affected version ranges, including fixes in OTP 27.3.4.13, 28.5.0.2, and 29.0.2, and characterized the issue primarily as denial of service.
A GitHub security advisory disclosed that a remote unauthenticated attacker could crash the Erlang BEAM VM with a crafted SCTP ERROR chunk under specific SCTP-enabled conditions, and noted limited memory disclosure and that Windows is unaffected.
A code change in erlang/otp introduced buffer-size tracking and truncation logic to protect the output term buffer during SCTP error and async event parsing, addressing the overflow condition.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourceosv.dev
Open sourcegithub.com
Open sourcecvefeed.io
Open sourcegithub.com
Open sourcecna.erlef.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.