CVE-2026-59250

8.3

Erlang · OTP

A buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to cause a denial of service or potentially execute arbitrary code via a crafted message.

Executive summary

A memory corruption vulnerability in the Erlang/OTP megaco flex scanner poses a high risk of service disruption or remote code execution by unauthenticated attackers.

Vulnerability

This is a classic buffer overflow (CWE-120) and out-of-bounds write (CWE-787) vulnerability located in the megaco flex scanner C driver, which can be triggered by an unauthenticated remote attacker sending a malformed, text-encoded message.

Business impact

The vulnerability carries a CVSS score of 8.3, reflecting the high potential for service instability. Successful exploitation allows for a denial-of-service crash or potential arbitrary code execution, which could lead to a complete compromise of the Erlang node, resulting in unauthorized data access or significant operational downtime for affected services.

Remediation

Immediate Action: Update Erlang/OTP to a patched version as specified in the vendor security advisory.

Proactive Monitoring: Monitor system logs for repeated crash events or unusual memory consumption patterns in the megaco driver.

Compensating Controls: Deploy network-level traffic filtering or WAF rules to inspect and drop malformed H.248/Megaco messages before they reach the Erlang application.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high CVSS severity and the remote nature of the attack vector, organizations should prioritize patching Erlang/OTP environments. If an immediate update is not feasible, restrict access to the affected service via network segmentation to minimize exposure to untrusted traffic.

More Erlang CVEs

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Fix documented version 27.3.4.15 per CVE record