Erlang OTP epmd DoS via FD exhaustion (before 27.3.4.15)
CVE-2026-42792 Published on July 27, 2026
epmd permanent DoS via EMFILE on accept(2) in erts
Improper Handling of Exceptional Conditions vulnerability in Erlang OTP erts (epmd) allows an unauthenticated remote attacker to permanently terminate the Erlang Port Mapper Daemon (epmd) via connection slot exhaustion.
The do_accept function in erts/epmd/src/epmd_srv.c calls epmd_cleanup_exit() when accept(2) returns EMFILE (per-process file descriptor limit reached) or ENFILE (system-wide file descriptor limit reached), rather than treating these as recoverable conditions. An attacker can exhaust epmd's file descriptor slots by holding many TCP connections open while periodically sending a single byte to reset the idle timeout, then causing accept(2) to return EMFILE, which kills the daemon. epmd has no per-source-IP connection cap, making the attack feasible from a single source.
On Debian/Ubuntu default packaging the impact is amplified: the systemd unit inherits a low file descriptor soft limit, and repeated daemon deaths trigger systemd's start-rate-limit, permanently failing both epmd.service and epmd.socket and requiring manual operator intervention to recover.
This issue affects OTP from OTP 17.0 before OTP 29.0.4, OTP 28.5.0.4 and OTP 27.3.4.15.
Weakness Types
Improper Handling of Exceptional Conditions
The software does not handle or incorrectly handles an exceptional condition.
Allocation of Resources Without Limits or Throttling
The software allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.
Products Associated with CVE-2026-42792
Want to know whenever a new CVE is published for Erlangotp? stack.watch will email you.
Affected Versions
Erlang OTP:- Version 6.0 and below * is affected.
- Version 17.0 and below * is affected.
- Version 07b8f441ca711f9812fad9e9115bab3c3aa92f79 and below 865d203e4a6a8f44179eced9e1428f9259e4a3bb is affected.