Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerability in Erlang OTP erts allows an attacker who can supply a crafted Erlang external term format (ETF) binary to binary_to_term/1 to corrupt the BEAM heap pointer and crash the virtual machine.
When decoding a LARGE_TUPLE_EXT term, the validation pass decoded_size() in erts/emulator/beam/external.c reads the 32-bit arity field as unsigned (get_uint32()), while the decode pass dec_term() reads the same field as a signed 32-bit integer (get_int32()) into an int. An arity wire value of 0x80000000 passes validation as 2147483648 but decodes as -2147483648, so the subsequent hp += n moves the heap allocation pointer backward. Neither pass enforces the runtime tuple-arity limit MAX_ARITYVAL. The result is an out-of-bounds heap write; in practice the VM detects an impossible heap size and aborts, denying service. The required padding is large when uncompressed but the compressed-ETF envelope shrinks it to a small payload on the wire.
This issue affects OTP from OTP 25.0 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15, corresponding to erts from 13.0 before 17.0.4, 16.4.0.4 and 15.2.7.11.
{
"capec_ids": [
"CAPEC-92"
],
"cpe_ids": [
"cpe:2.3:a:erlang:erlang\\/otp:*:*:*:*:*:*:*:*"
],
"cwe_ids": [
"CWE-195",
"CWE-787"
]
}"https://cna.erlef.org/osv/EEF-CVE-2026-55737.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "274620051191622708189806810367620417122",
"length": 18355
},
"id": "EEF-CVE-2026-55737-37372609",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/erlang/otp/commit/c5210b42a9d3d96f3d25601942ce8122be0f3761",
"target": {
"file": "erts/emulator/beam/external.c",
"function": "dec_term"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "151631869666417194889055200798638607449",
"length": 7049
},
"id": "EEF-CVE-2026-55737-61690b93",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/erlang/otp/commit/c5210b42a9d3d96f3d25601942ce8122be0f3761",
"target": {
"file": "erts/emulator/beam/external.c",
"function": "decoded_size"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"163280457750676734900279870991134780414",
"122596077993829045550579153013852990028",
"14546037783706032069697512902558977241",
"94422143658124507221783098213955201150",
"306942062293879953335362107754943078575",
"245130003002038853262703291213551869868",
"9771150500771257063044300031309272034",
"236013294772006922695479952280560046841",
"249120499072289816206395365375493616732",
"104431137102872275312802688813124292002",
"197094389993450959993925167799689180472",
"49081135807654127949625384542412245608"
],
"threshold": 0.9
},
"id": "EEF-CVE-2026-55737-fc08d775",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/erlang/otp/commit/c5210b42a9d3d96f3d25601942ce8122be0f3761",
"target": {
"file": "erts/emulator/beam/external.c"
}
}
]
"2026-08-03T20:02:03Z"