CVE-2026-42792
Received Received - Intake

Denial of Service in Erlang OTP epmd

Vulnerability report for CVE-2026-42792, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: EEF

Description

Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to permanently terminate the Erlang Port Mapper Daemon (epmd) via connection slot exhaustion. The do_accept function in erts/epmd/src/epmd_srv.c calls epmd_cleanup_exit() when accept(2) returns EMFILE (per-process file descriptor limit reached) or ENFILE (system-wide file descriptor limit reached), rather than treating these as recoverable conditions. An attacker can exhaust epmd's file descriptor slots by holding many TCP connections open while periodically sending a single byte to reset the idle timeout, then causing accept(2) to return EMFILE, which kills the daemon. epmd has no per-source-IP connection cap, making the attack feasible from a single source. On Debian/Ubuntu default packaging the impact is amplified: the systemd unit inherits a low file descriptor soft limit, and repeated daemon deaths trigger systemd's start-rate-limit, permanently failing both epmd.service and epmd.socket and requiring manual operator intervention to recover. This issue affects OTP from OTP 17.0 before OTPΒ 29.0.4, OTPΒ 28.5.0.4 and OTPΒ 27.3.4.15.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
erlang otp 17.0
erlang otp 28.5.0.4
erlang otp 27.3.4.15
erlang otp From 17.0|end_excluding=29.0.4 (inc)
erlang otp to 29.0.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-755 The product does not handle or incorrectly handles an exceptional condition.
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-42792 is a denial-of-service vulnerability in Erlang OTP's Erlang Port Mapper Daemon (epmd). It occurs when epmd's do_accept function terminates the daemon permanently if system file descriptor limits are reached during connection attempts. An attacker can exploit this by opening many TCP connections, forcing epmd to crash repeatedly.

Detection Guidance

Monitor epmd service status and file descriptor usage. Check for repeated crashes of epmd.service or epmd.socket. Use netstat or ss to inspect active connections to TCP port 4369. Check system logs for EMFILE or ENFILE errors in epmd processes.

Impact Analysis

This vulnerability can cause epmd to crash repeatedly, disrupting Erlang node communication. On Debian/Ubuntu systems, repeated crashes may trigger systemd's start-rate-limit, permanently disabling epmd until manual intervention. Services relying on epmd may fail.

Compliance Impact

This vulnerability could indirectly impact compliance with GDPR and HIPAA by causing service disruptions. A DoS attack on epmd may lead to unavailability of Erlang-based services, potentially violating availability requirements in GDPR (Article 32) and HIPAA (Security Rule Β§164.308(a)(7)). Prolonged downtime due to repeated daemon crashes could result in unauthorized access or data processing interruptions, affecting integrity and confidentiality.

Mitigation Strategies

Upgrade Erlang OTP to patched versions (27.3.4.15, 28.5.0.4, or 29.0.4). Restrict epmd to loopback interface via systemd socket overrides. Increase file descriptor limits and enable automatic restarts. Block external access to TCP port 4369 using firewall rules.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-42792. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart