{"id":"AZL-90114","summary":"CVE-2026-49760 affecting package erlang for versions less than 26.2.5.21-2","details":"Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow.\n\nThis vulnerability is associated with program file lib/erl_interface/src/misc/ei_printterm.c and program routine ei_s_print_term.\n\nThe C function ei_s_print_term uses an internal 2000-character stack buffer to format terms. When called with an encoded Erlang term containing a very large integer (encoded representation exceeding 2000 characters), the buffer overflows. The overflow bytes are restricted to the ASCII values of 0-9 and A-F, which limits exploitation to Denial of Service.\n\nThe companion function ei_print_term, which prints directly to a FILE instead of a memory buffer, does not contain this bug.\n\nThis issue affects OTP from OTP 17.0 before OTP 29.0.2, OTP 28.5.0.2 and OTP 27.3.4.13, corresponding to erl_interface from 3.7.16 before 5.8.1, 5.7.0.1 and 5.5.2.1.","modified":"2026-08-30T05:26:50Z","published":"2026-06-10T16:17:12Z","upstream":["CVE-2026-49760"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49760"}],"affected":[{"package":{"name":"erlang","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/erlang"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"26.2.5.21-2"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-90114.json"}}],"schema_version":"1.9.0"}