CVE-2026-42792 is a vulnerability in the Erlang epmd service that allows an attacker to permanently deny service via the EMFILE error, exploiting CWE-755: Improper Handling of Exceptional Conditions. This flaw can be triggered when the accept(2) function returns an EMFILE error, causing the service to crash and become unresponsive. The business impact of this vulnerability is moderate, as it can lead to denial-of-service attacks against systems relying on the epmd service. Affected versions include those prior to 26.2.5.21-4, which includes Azure Linux 3.0. Exploiting this flaw does not require any special privileges or user interaction, making it a potential threat to systems running vulnerable versions of Erlang epmd. This vulnerability can be exploited through various attack vectors, including network-based attacks, which highlights the need for robust security measures to prevent such incidents. Users should be aware of this vulnerability and take necessary precautions to mitigate its impact.
We recommend you to refer below link: https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42792[/subscribe_to_unlock_form]
CVE-2026-42792 is a vulnerability in the Erlang epmd service that allows an attacker to permanently deny service via the EMFILE error, exploiting CWE-755: Improper Handling of Exceptional Conditions. This flaw can be triggered when the accept(2) function returns an EMFILE error, causing the service to crash and become unresponsive. The business impact of this vulnerability is moderate, as it can lead to denial-of-service attacks against systems relying on the epmd service. Affected versions include those prior to 26.2.5.21-4, which includes Azure Linux 3.0. Exploiting this flaw does not require any special privileges or user interaction, making it a potential threat to systems running vulnerable versions of Erlang epmd. This vulnerability can be exploited through various attack vectors, including network-based attacks, which highlights the need for robust security measures to prevent such incidents. Users should be aware of this vulnerability and take necessary precautions to mitigate its impact.
We recommend you to refer below link: https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-42792[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]