CVE-2026-55737 PUBLISHED

Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder

Assigner: EEF
Reserved: 17.06.2026 Published: 27.07.2026 Updated: 27.07.2026

Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can supply a crafted Erlang external term format (ETF) binary to binary_to_term/1 to corrupt the BEAM heap pointer and crash the virtual machine.

When decoding a LARGE_TUPLE_EXT term, the validation pass decoded_size() in erts/emulator/beam/external.c reads the 32-bit arity field as unsigned (get_uint32()), while the decode pass dec_term() reads the same field as a signed 32-bit integer (get_int32()) into an int. An arity wire value of 0x80000000 passes validation as 2147483648 but decodes as -2147483648, so the subsequent hp += n moves the heap allocation pointer backward. Neither pass enforces the runtime tuple-arity limit MAX_ARITYVAL. The result is an out-of-bounds heap write; in practice the VM detects an impossible heap size and aborts, denying service. The required padding is large when uncompressed but the compressed-ETF envelope shrinks it to a small payload on the wire.

This issue affects OTP from OTP 25.0 before 27.3.4.15, 28.5.0.4, and 29.0.4 corresponding to erts from 13.0 before 15.2.7.11, 16.4.0.4, and 17.0.4.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 5.1

Product Status

Vendor Erlang
Product OTP
Versions Default: unaffected
  • affected from 13.0 to * (excl.)
Vendor Erlang
Product OTP
Versions Default: unaffected
  • affected from 25.0 to * (excl.)
  • affected from ebcbb97b4ec223464cac3d94375739a248ddef6e to c5210b42a9d3d96f3d25601942ce8122be0f3761 (excl.)

Credits

  • Nick Gunn finder
  • Kiko Fernandez-Reyes remediation developer
  • Sverker Eriksson remediation reviewer

References

Problem Types

  • CWE-195 Signed to Unsigned Conversion Error CWE
  • CWE-787 Out-of-bounds Write CWE

Impacts

  • CAPEC-92 Forced Integer Overflow