CVE-2026-59250

Publication date 27 July 2026

Last updated 28 September 2026


Ubuntu priority

Description

Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver allows a remote unauthenticated attacker to corrupt the driver's memory (and potentially achieve remote code execution or a denial-of-service crash) by sending a single text-encoded H.248/Megaco message containing an oversized property parm name. When tokenizing a Local/Remote descriptor, mfs_load_property_groups extracts the attacker-controlled property name (bounded only by the message length) and, when no value follows, formats it into a fixed 512-byte error_msg field of the MfsErlDrvData struct using an unchecked sprintf call. Names longer than roughly 452 bytes overflow into the immediately following struct fields (text_buf, text_ptr, term_spec, term_spec_size, term_spec_index), overwriting live pointers and counters with attacker-chosen bytes. Subsequent scanner code writes and frees through the corrupted pointers, producing arbitrary write and arbitrary free primitives inside the BEAM VM process, which can be leveraged for remote code execution. On builds compiled with _FORTIFY_SOURCE the overflow is detected at runtime and terminates the process with SIGABRT, resulting in denial of service. The overflow occurs in the flex scanner before any grammar or Megaco-level authentication processing, so exploitation requires only network reachability to the megaco transport port on a node configured with {scanner, flex}. This vulnerability is associated with program files lib/megaco/src/flex/megaco_flex_scanner_drv.flex.src and program routines mfs_load_property_groups. This issue affects OTP from OTP 17.0 before OTP 27.3.4.15, from OTP 28.0 before OTP 28.5.0.4, and from OTP 29.0 before OTP 29.0.4, corresponding to megaco from 3.17.1 before 4.7.2.2, from 4.8 before 4.8.3.1, and from 4.9 before 4.9.1. Whether OTP before OTP 17.0, corresponding to megaco before 3.17.1, is affected is unknown.

Status

Package Ubuntu Release Status
erlang 26.04 LTS resolute
Fixed 1:27.3.4.6+dfsg-1ubuntu0.1
24.04 LTS noble
Fixed 1:25.3.2.8+dfsg-1ubuntu4.7
22.04 LTS jammy
Fixed 1:24.2.1+dfsg-1ubuntu0.7
20.04 LTS focal
Fixed 1:22.2.7+dfsg-1ubuntu0.5+esm2
18.04 LTS bionic
Fixed 1:20.2.2+dfsg-1ubuntu2+esm3
16.04 LTS xenial
Fixed 1:18.3-dfsg-1ubuntu3.1+esm3
14.04 LTS trusty
Fixed 1:16.b.3-dfsg-1ubuntu2.2+esm2

Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

Get Ubuntu Pro 30-day free trial

Patch details

For informational purposes only. We recommend not to cherry-pick updates. How can I get the fixes?

Package Patch details
erlang

Severity score breakdown

CVSS version: CVSS v4.0

Base score 8.3 · High

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N

References

Related Ubuntu Security Notices (USN)

    • USN-8827-1
    • Erlang vulnerabilities
    • 28 September 2026

Other references


Access our resources on patching vulnerabilities