CVE-2016-10253: Erlang Erlang/otp
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions using a malformed extpattern can indirectly specify an offset that is used as an array index. This ordinal permits arbitrary regions within the erts_alloc arena to be both read and written to.
Affected products
- Erlang Erlang/otp: version 18.0 only; version 18.0.1 only; version 18.0.2 only; version 18.0.3 only; version 18.1 only; version 18.1.1 only; …
Published 2017-03-18. Last modified 2026-06-17.