{"affected":[{"ranges":[{"events":[{"introduced":"ebcbb97b4ec223464cac3d94375739a248ddef6e"},{"fixed":"c5210b42a9d3d96f3d25601942ce8122be0f3761"}],"repo":"https://github.com/erlang/otp","type":"GIT"}]}],"aliases":["GHSA-446w-268v-9462","CVE-2026-55737"],"credits":[{"name":"Nick Gunn","type":"FINDER"},{"name":"Kiko Fernandez-Reyes","type":"REMEDIATION_DEVELOPER"},{"name":"Sverker Eriksson","type":"REMEDIATION_REVIEWER"}],"database_specific":{"capec_ids":["CAPEC-92"],"cpe_ids":["cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"],"cwe_ids":["CWE-195","CWE-787"]},"details":"## Summary\n\nSigned to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can supply a crafted Erlang external term format (ETF) binary to binary\\_to\\_term/1 to corrupt the BEAM heap pointer and crash the virtual machine.\n\nWhen decoding a LARGE\\_TUPLE\\_EXT term, the validation pass decoded\\_size() in erts/emulator/beam/external.c reads the 32-bit arity field as unsigned (get\\_uint32()), while the decode pass dec\\_term() reads the same field as a signed 32-bit integer (get\\_int32()) into an int. An arity wire value of 0x80000000 passes validation as 2147483648 but decodes as -2147483648, so the subsequent hp += n moves the heap allocation pointer backward. Neither pass enforces the runtime tuple-arity limit MAX\\_ARITYVAL. The result is an out-of-bounds heap write; in practice the VM detects an impossible heap size and aborts, denying service. The required padding is large when uncompressed but the compressed-ETF envelope shrinks it to a small payload on the wire.\n\nThis issue affects OTP from OTP 25.0 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15, corresponding to erts from 13.0 before 17.0.4, 16.4.0.4 and 15.2.7.11.","id":"EEF-CVE-2026-55737","modified":"2026-07-27T16:11:37.001Z","published":"2026-07-27T15:13:54.699Z","references":[{"type":"ADVISORY","url":"https://github.com/erlang/otp/security/advisories/GHSA-446w-268v-9462"},{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-55737.html"},{"type":"WEB","url":"https://www.erlang.org/doc/system/versions.html#order-of-versions"},{"type":"FIX","url":"https://github.com/erlang/otp/commit/c5210b42a9d3d96f3d25601942ce8122be0f3761"}],"related":[],"schema_version":"1.7.3","severity":[{"score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","type":"CVSS_V4"}],"summary":"Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder","upstream":[]}