{"schema_version":"1.9.0","id":"CVE-2026-49760","published":"2026-06-10T14:35:36.804Z","modified":"2026-08-21T09:27:02.478284803Z","aliases":["EEF-CVE-2026-49760","GHSA-xcxj-5pg2-v72j"],"related":["SUSE-SU-2026:3579-1","SUSE-SU-2026:3645-1","openSUSE-SU-2026:11559-1","openSUSE-SU-2026:11560-1"],"summary":"Stack Buffer Overflow in ei_s_print_term at Very Large Integer","details":"Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow.\n\nThis vulnerability is associated with program file lib/erl_interface/src/misc/ei_printterm.c and program routine ei_s_print_term.\n\nThe C function ei_s_print_term uses an internal 2000-character stack buffer to format terms. When called with an encoded Erlang term containing a very large integer (encoded representation exceeding 2000 characters), the buffer overflows. The overflow bytes are restricted to the ASCII values of 0-9 and A-F, which limits exploitation to Denial of Service.\n\nThe companion function ei_print_term, which prints directly to a FILE instead of a memory buffer, does not contain this bug.\n\nThis issue affects OTP from OTP 17.0 before OTP 29.0.2, OTP 28.5.0.2 and OTP 27.3.4.13, corresponding to erl_interface from 3.7.16 before 5.8.1, 5.7.0.1 and 5.5.2.1.","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/erlang/otp","events":[{"introduced":"07b8f441ca711f9812fad9e9115bab3c3aa92f79"},{"fixed":"f835a5a32aeeb70778c958b5c01a401973e8fbe2"},{"introduced":"9e6f6742c4d9e9915ee8af0dcb7d97cf1f836116"},{"fixed":"4567096bddd1ecddb7c973019ca7e769f486aa8f"},{"introduced":"550d7b7898706c7822362c42e7b93120c1d1f29a"},{"fixed":"36b336d7675edfb976768465c5067bc8bc16ee9a"},{"fixed":"0bef277b2d39dc8babb9ceb4f5d0a456f3007111"}],"database_specific":{"cpe":"cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"17.0"},{"fixed":"27.3.4.13"},{"introduced":"28.0"},{"fixed":"28.5.0.2"},{"introduced":"29.0"},{"fixed":"29.0.2"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["OTP-29.0","patch-base-28","OTP-28.5","patch-base-27","OTP-27.3.4","OTP-28.4","OTP-27.3.4.12","OTP-28.5.0.1","OTP-29.0.1","OTP-27.3.4.9","OTP-27.0","patch-base-26","OTP-26.2.5","OTP-27.3.4.11","OTP-27.3.4.10","OTP-28.0","OTP-27.3.4.8","OTP-27.3.4.6","OTP-27.3.4.7","OTP-27.3","OTP-27.3.4.5","OTP-27.3.4.4","OTP-26.2.3","OTP-28.1","OTP-27.3.4.3","OTP-27.3.3","OTP-27.3.4.2","OTP-26.0","OTP-25.0","OTP-27.3.4.1","OTP-27.3.2","OTP-27.2","OTP-27.3.1","OTP-27.1","OTP-26.2","OTP-26.2.4","OTP-27.0-rc3","OTP-27.0-rc2","OTP-27.0-rc1","OTP-24.0","OTP-26.1","OTP-26.0-rc3","OTP-26.0-rc2","OTP-26.0-rc1","OTP-23.0","OTP-21.0","OTP-25.0-rc3","OTP-25.0-rc2","OTP-25.0-rc1","OTP-22.0","OTP-24.0-rc3","OTP-24.0-rc2","OTP-24.0-rc1","OTP-23.0-rc3","OTP-23.0-rc2","OTP-23.0-rc1","OTP-20.0","OTP-22.0-rc3","OTP-22.0-rc2","OTP-22.0-rc1","OTP-19.0","OTP-21.0-rc2","OTP-18.0","OTP-21.0-rc1","OTP-17.0","OTP-20.0-rc2","OTP-20.0-rc1","OTP-19.0-rc2","OTP-19.0-rc1","OTP-18.0-rc1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-49760.json","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"193368618758297330893065608929158335242","length":186},"id":"CVE-2026-49760-022411e5","signature_type":"Function","signature_version":"v1","source":"https://github.com/erlang/otp/commit/0bef277b2d39dc8babb9ceb4f5d0a456f3007111","target":{"file":"lib/erl_interface/src/misc/ei_printterm.c","function":"xputs"}},{"deprecated":false,"digest":{"line_hashes":["129987449935442626922576360273010985950","182628357533292467603230335496893584182","84974574094128217425849947334958450591","303204613610604044333794037154847545087","205505750195805099599079314046653074886","242411142061672716631652253432456926320","34229576740430111543674439228487913588","206948010257539244208078656576434751129","299580921524496072993945454093677126032","124508628327946877418788548966952760392","36321982408223680249605131387021290611","244093350943159726189524618619533006355","128472681028884791199717162918156810034","48089500669397162200594149588556148739","327409299815393523873394638738727266457","222125189150859468688246895535557614247","160518933820097368485581825050040697410","74763268382742076537110950297602582020"],"threshold":0.9},"id":"CVE-2026-49760-050c4019","signature_type":"Line","signature_version":"v1","source":"https://github.com/erlang/otp/commit/0bef277b2d39dc8babb9ceb4f5d0a456f3007111","target":{"file":"lib/erl_interface/src/misc/ei_printterm.c"}},{"deprecated":false,"digest":{"function_hash":"20126977231981737495608613980381006874","length":355},"id":"CVE-2026-49760-5c3d14ea","signature_type":"Function","signature_version":"v1","source":"https://github.com/erlang/otp/commit/0bef277b2d39dc8babb9ceb4f5d0a456f3007111","target":{"file":"lib/erl_interface/src/misc/ei_printterm.c","function":"xprintf"}},{"deprecated":false,"digest":{"function_hash":"248798747059463741358854413735715547791","length":6224},"id":"CVE-2026-49760-61f1ec93","signature_type":"Function","signature_version":"v1","source":"https://github.com/erlang/otp/commit/0bef277b2d39dc8babb9ceb4f5d0a456f3007111","target":{"file":"lib/erl_interface/src/misc/ei_printterm.c","function":"print_term"}},{"deprecated":false,"digest":{"function_hash":"257318524130605958237752132322241258155","length":771},"id":"CVE-2026-49760-626a3fb8","signature_type":"Function","signature_version":"v1","source":"https://github.com/erlang/otp/commit/0bef277b2d39dc8babb9ceb4f5d0a456f3007111","target":{"file":"lib/erl_interface/test/ei_print_SUITE_data/ei_print_test.c","function":"send_printed_buf"}},{"deprecated":false,"digest":{"line_hashes":["264093821237804837996415942465318863659","10424607488912900977757057427559227229","218318064356773586102645165312208352557","71546891966718475353985029582207272855","189936519407021833390469519939506059547","198264497833074430851461912828825666618","270754654748745929540968422776954156395","180603470982765993879983251533839877765","214801972202090556207145028581013595147","277430019812868477916019892760205087535","118908469996054890492759544605081118760","26330492287504809149405060904030128303","360159136364441462841237574318458360","131442704667594904828977963152148302858","329851795378938511090137206008449770983","178423773278323329577470179964423923363","221256189197817541730556399113524709619","42519436959816468196649549280584202425","12786333625252033611733634326801589262","190912576496919874105935446397243018492","105145191943495785581530336704990414754","48877447683709588715041790956971934178","59253891848884251319204915152001355112","148581509704816979468765201139810176747","268372373344873455942867287554750212163","273948230403692249289307622996310571929","134965975837835266064335129159271436049","273479961572098031058391051095752582635"],"threshold":0.9},"id":"CVE-2026-49760-b0b91ab0","signature_type":"Line","signature_version":"v1","source":"https://github.com/erlang/otp/commit/0bef277b2d39dc8babb9ceb4f5d0a456f3007111","target":{"file":"lib/erl_interface/test/ei_print_SUITE_data/ei_print_test.c"}}],"vanir_signatures_modified":"2026-08-12T16:09:42Z"}}],"references":[{"type":"WEB","url":"https://cna.erlef.org/cves/CVE-2026-49760.html"},{"type":"WEB","url":"https://github.com"},{"type":"WEB","url":"https://osv.dev/vulnerability/EEF-CVE-2026-49760"},{"type":"WEB","url":"https://www.erlang.org/doc/system/versions.html#order-of-versions"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49760.json"},{"type":"ADVISORY","url":"https://github.com/erlang/otp/security/advisories/GHSA-xcxj-5pg2-v72j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49760"},{"type":"FIX","url":"https://github.com/erlang/otp/commit/0bef277b2d39dc8babb9ceb4f5d0a456f3007111"},{"type":"PACKAGE","url":"https://github.com/erlang/otp"}],"database_specific":{"cna_assigner":"EEF","cwe_ids":["CWE-121"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/49xxx/CVE-2026-49760.json","unresolved_ranges":[{"extracted_events":[{"introduced":"3.7.16"},{"fixed":"*"},{"introduced":"17.0"},{"fixed":"*"},{"introduced":"84adefa331c4159d432d22840663c38f155cd4c1"},{"fixed":"0bef277b2d39dc8babb9ceb4f5d0a456f3007111"}],"source":"AFFECTED_FIELD"}]},"severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}