What is CVE-2026-59250?
This CVE describes a classic buffer overflow vulnerability in the Erlang/OTP megaco flex scanner C driver. A remote unauthenticated attacker can corrupt driver memory, potentially leading to remote code execution (RCE) or denial-of-service (DoS), by sending a specially crafted H.248/Megaco message with an oversized parameter. Applying security patches is strongly recommended for affected systems.
Azərbaycanca: Bu CVE, Erlang/OTP-nin megaco flex skaner C sürücüsündə klassik bufer daşması (buffer overflow) zəifliyini təsvir edir. Uzaqdan autentifikasiya olunmamış hücumçu, həddən artıq böyük parametr daşıyan xüsusi hazırlanmış H.248/Megaco mesajı göndərərək yaddaş pozuntusuna, xidmət rəddinə (DoS) və ya potensial kod icrasına (RCE) nail ola bilər. Təsirə məruz qalan sistemlərdə təhlükəsizlik yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
Does exploiting CVE-2026-59250 require authentication?
No, this vulnerability can be exploited remotely without authentication. An attacker can affect the target system by sending a specially crafted H.248/Megaco message.
Which component of Erlang/OTP is affected by CVE-2026-59250?
This vulnerability is a classic buffer overflow located in the megaco flex scanner C driver of Erlang/OTP. A message carrying an oversized parameter leads to memory corruption.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.