{"id":"CVE-2026-55737","summary":"Heap pointer corruption via signed/unsigned mismatch in LARGE_TUPLE_EXT decoding in erts external term format decoder","details":"Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can supply a crafted Erlang external term format (ETF) binary to binary_to_term/1 to corrupt the BEAM heap pointer and crash the virtual machine.\n\nWhen decoding a LARGE_TUPLE_EXT term, the validation pass decoded_size() in erts/emulator/beam/external.c reads the 32-bit arity field as unsigned (get_uint32()), while the decode pass dec_term() reads the same field as a signed 32-bit integer (get_int32()) into an int. An arity wire value of 0x80000000 passes validation as 2147483648 but decodes as -2147483648, so the subsequent hp += n moves the heap allocation pointer backward. Neither pass enforces the runtime tuple-arity limit MAX_ARITYVAL. The result is an out-of-bounds heap write; in practice the VM detects an impossible heap size and aborts, denying service. The required padding is large when uncompressed but the compressed-ETF envelope shrinks it to a small payload on the wire.\n\nThis issue affects OTP from OTP 25.0 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15, corresponding to erts from 13.0 before 17.0.4, 16.4.0.4 and 15.2.7.11.","aliases":["EEF-CVE-2026-55737","GHSA-446w-268v-9462"],"modified":"2026-08-01T08:23:07.878055Z","published":"2026-07-27T15:13:54.699Z","database_specific":{"cna_assigner":"EEF","cwe_ids":["CWE-195","CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55737.json","unresolved_ranges":[{"extracted_events":[{"introduced":"13.0"},{"fixed":"*"},{"introduced":"25.0"},{"fixed":"*"},{"introduced":"ebcbb97b4ec223464cac3d94375739a248ddef6e"},{"fixed":"c5210b42a9d3d96f3d25601942ce8122be0f3761"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-55737.html"},{"type":"WEB","url":"https://github.com"},{"type":"WEB","url":"https://osv.dev/vulnerability/EEF-CVE-2026-55737"},{"type":"WEB","url":"https://www.erlang.org/doc/system/versions.html#order-of-versions"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55737.json"},{"type":"ADVISORY","url":"https://github.com/erlang/otp/security/advisories/GHSA-446w-268v-9462"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55737"},{"type":"FIX","url":"https://github.com/erlang/otp/commit/c5210b42a9d3d96f3d25601942ce8122be0f3761"},{"type":"PACKAGE","url":"https://github.com/erlang/otp"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/erlang/otp","events":[{"introduced":"4ed7957623e5ccbd420a09a506bd6bc9930fe93c"},{"introduced":"9e6f6742c4d9e9915ee8af0dcb7d97cf1f836116"},{"introduced":"550d7b7898706c7822362c42e7b93120c1d1f29a"},{"fixed":"8def54e66dfdd41c535272794d49cc633f596d22"},{"fixed":"6cfd400a2379163a2802f376d3b3d02f815d34c0"},{"fixed":"1259612946cb36a8bf9614b289090bb32fbcbeb2"},{"fixed":"c5210b42a9d3d96f3d25601942ce8122be0f3761"}],"database_specific":{"extracted_events":[{"introduced":"25.0"},{"fixed":"27.3.4.15"},{"introduced":"28.0"},{"fixed":"28.5.0.4"},{"introduced":"29.0"},{"fixed":"29.0.4"}],"source":["CPE_FIELD","REFERENCES"]}}],"versions":["OTP-29.0.3","OTP-28.5.0.3","OTP-27.3.4.14","patch-base-28","OTP-28.5","patch-base-27","OTP-27.3.4","OTP-27.3.4.13","OTP-28.5.0.2","OTP-29.0.2","OTP-28.4","OTP-27.3.4.12","OTP-28.5.0.1","OTP-29.0.1","OTP-29.0","OTP-27.3.4.9","OTP-27.0","OTP-27.3.4.11","OTP-27.3.4.10","OTP-28.0","OTP-27.3.4.8","OTP-27.3.4.6","OTP-27.3.4.7","OTP-27.3","OTP-27.3.4.5","OTP-27.3.4.4","OTP-28.1","OTP-27.3.4.3","OTP-27.3.3","OTP-27.3.4.2","OTP-26.0","OTP-25.0","OTP-27.3.4.1","OTP-27.3.2","OTP-27.2","OTP-27.3.1","OTP-27.1","OTP-27.0-rc3","OTP-27.0-rc2","OTP-27.0-rc1","OTP-26.0-rc3","OTP-26.0-rc2","OTP-26.0-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55737.json","vanir_signatures_modified":"2026-08-01T08:23:07Z","vanir_signatures":[{"source":"https://github.com/erlang/otp/commit/c5210b42a9d3d96f3d25601942ce8122be0f3761","target":{"file":"erts/emulator/beam/external.c","function":"dec_term"},"deprecated":false,"digest":{"function_hash":"274620051191622708189806810367620417122","length":18355},"id":"CVE-2026-55737-37372609","signature_type":"Function","signature_version":"v1"},{"target":{"file":"erts/emulator/beam/external.c","function":"decoded_size"},"deprecated":false,"digest":{"function_hash":"151631869666417194889055200798638607449","length":7049},"id":"CVE-2026-55737-61690b93","signature_type":"Function","signature_version":"v1","source":"https://github.com/erlang/otp/commit/c5210b42a9d3d96f3d25601942ce8122be0f3761"},{"source":"https://github.com/erlang/otp/commit/c5210b42a9d3d96f3d25601942ce8122be0f3761","target":{"file":"erts/emulator/beam/external.c"},"deprecated":false,"digest":{"line_hashes":["163280457750676734900279870991134780414","122596077993829045550579153013852990028","14546037783706032069697512902558977241","94422143658124507221783098213955201150","306942062293879953335362107754943078575","245130003002038853262703291213551869868","9771150500771257063044300031309272034","236013294772006922695479952280560046841","249120499072289816206395365375493616732","104431137102872275312802688813124292002","197094389993450959993925167799689180472","49081135807654127949625384542412245608"],"threshold":0.9},"id":"CVE-2026-55737-fc08d775","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}