FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Erlang/OTP -- heap corruption decoding invalidly encoded large tuples

Affected packages
erlang < 28.5.0.4,4
erlang-runtime27 < 27.3.4.15
erlang-runtime28 < 28.5.0.4
erlang-runtime29 < 29.0.4

Details

VuXML ID 445df078-89e1-11f1-b35c-4c526214c986
Discovery 2026-07-27
Entry 2026-07-27

The Erlang/OTP team reports:

Fixed heap corruption when an invalidly encoded tuple with an arity of 2^31 or larger is decoded from Erlang's External Term Format (binary_to_term).

References

CVE Name CVE-2026-55737
URL https://github.com/erlang/otp/releases/tag/OTP-29.0.4