Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can supply a crafted Erlang external term format (ETF) binary to binarytoterm/1 to corrupt the BEAM heap pointer and crash the virtual machine.
When decoding a LARGETUPLEEXT term, the validation pass decodedsize() in erts/emulator/beam/external.c reads the 32-bit arity field as unsigned (getuint32()), while the decode pass decterm() reads the same field as a signed 32-bit integer (getint32()) into an int. An arity wire value of 0x80000000 passes validation as 2147483648 but decodes as -2147483648, so the subsequent hp += n moves the heap allocation pointer backward. Neither pass enforces the runtime tuple-arity limit MAX_ARITYVAL. The result is an out-of-bounds heap write; in practice the VM detects an impossible heap size and aborts, denying service. The required padding is large when uncompressed but the compressed-ETF envelope shrinks it to a small payload on the wire.
This issue affects OTP from OTP 25.0 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15, corresponding to erts from 13.0 before 17.0.4, 16.4.0.4 and 15.2.7.11.
{
"cna_assigner": "EEF",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55737.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "13.0"
},
{
"fixed": "*"
},
{
"introduced": "25.0"
},
{
"fixed": "*"
},
{
"introduced": "ebcbb97b4ec223464cac3d94375739a248ddef6e"
},
{
"fixed": "c5210b42a9d3d96f3d25601942ce8122be0f3761"
}
],
"source": "AFFECTED_FIELD"
},
{
"extracted_events": [
{
"introduced": "25.0"
},
{
"fixed": "27.3.4.15"
},
{
"introduced": "28.0"
},
{
"fixed": "28.5.0.4"
},
{
"introduced": "29.0"
},
{
"fixed": "29.0.4"
}
],
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"introduced": "25.0"
},
{
"introduced": "13.0"
},
{
"fixed": "17.0.4"
}
],
"source": "DESCRIPTION"
}
],
"cwe_ids": [
"CWE-195",
"CWE-787"
]
}"2026-07-29T08:20:17Z"
[
{
"target": {
"function": "dec_term",
"file": "erts/emulator/beam/external.c"
},
"id": "CVE-2026-55737-37372609",
"digest": {
"function_hash": "274620051191622708189806810367620417122",
"length": 18355.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/erlang/otp/commit/c5210b42a9d3d96f3d25601942ce8122be0f3761"
},
{
"target": {
"function": "decoded_size",
"file": "erts/emulator/beam/external.c"
},
"id": "CVE-2026-55737-61690b93",
"digest": {
"function_hash": "151631869666417194889055200798638607449",
"length": 7049.0
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Function",
"source": "https://github.com/erlang/otp/commit/c5210b42a9d3d96f3d25601942ce8122be0f3761"
},
{
"target": {
"file": "erts/emulator/beam/external.c"
},
"id": "CVE-2026-55737-fc08d775",
"digest": {
"line_hashes": [
"163280457750676734900279870991134780414",
"122596077993829045550579153013852990028",
"14546037783706032069697512902558977241",
"94422143658124507221783098213955201150",
"306942062293879953335362107754943078575",
"245130003002038853262703291213551869868",
"9771150500771257063044300031309272034",
"236013294772006922695479952280560046841",
"249120499072289816206395365375493616732",
"104431137102872275312802688813124292002",
"197094389993450959993925167799689180472",
"49081135807654127949625384542412245608"
],
"threshold": 0.9
},
"deprecated": false,
"signature_version": "v1",
"signature_type": "Line",
"source": "https://github.com/erlang/otp/commit/c5210b42a9d3d96f3d25601942ce8122be0f3761"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55737.json"