CVE-2016-10253: Erlang Erlang/otp

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

An issue was discovered in Erlang/OTP 18.x. Erlang's generation of compiled regular expressions is vulnerable to a heap overflow. Regular expressions using a malformed extpattern can indirectly specify an offset that is used as an array index. This ordinal permits arbitrary regions within the erts_alloc arena to be both read and written to.

Affected products

  • Erlang Erlang/otp: version 18.0 only; version 18.0.1 only; version 18.0.2 only; version 18.0.3 only; version 18.1 only; version 18.1.1 only; …

Published 2017-03-18. Last modified 2026-06-17.