CVE-2026-42792
Gravedad CVSS v4.0:
MEDIA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
27/07/2026
Última modificación:
27/07/2026
Descripción
*** Pendiente de traducción *** Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to permanently terminate the Erlang Port Mapper Daemon (epmd) via connection slot exhaustion.<br />
<br />
The do_accept function in erts/epmd/src/epmd_srv.c calls epmd_cleanup_exit() when accept(2) returns EMFILE (per-process file descriptor limit reached) or ENFILE (system-wide file descriptor limit reached), rather than treating these as recoverable conditions. An attacker can exhaust epmd&#39;s file descriptor slots by holding many TCP connections open while periodically sending a single byte to reset the idle timeout, then causing accept(2) to return EMFILE, which kills the daemon. epmd has no per-source-IP connection cap, making the attack feasible from a single source.<br />
<br />
On Debian/Ubuntu default packaging the impact is amplified: the systemd unit inherits a low file descriptor soft limit, and repeated daemon deaths trigger systemd&#39;s start-rate-limit, permanently failing both epmd.service and epmd.socket and requiring manual operator intervention to recover.<br />
<br />
This issue affects OTP from OTP 17.0 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15.
Impacto
Puntuación base 4.0
6.30
Gravedad 4.0
MEDIA
Referencias a soluciones, herramientas e información
- https://cna.erlef.org/cves/CVE-2026-42792.html
- https://github.com/erlang/otp/commit/865d203e4a6a8f44179eced9e1428f9259e4a3bb
- https://github.com/erlang/otp/security/advisories/GHSA-h6f3-hx58-xhj6
- https://osv.dev/vulnerability/EEF-CVE-2026-42792
- https://www.erlang.org/doc/system/versions.html#order-of-versions



