Impact
A TLS/DTLS peer can crash the remote node by sending a certificate chain containing two mutually cross-signed certificates in unordered form. When the receiving side attempts to build a valid chain path, it enters unbounded recursion between the two certificates (A issues B, B issues A) with no cycle detection or depth limit. The call stack and chain accumulator grow without bound until the process exhausts available memory and the BEAM node crashes. The attack requires only a TCP connection and a partial handshake — no authentication or completed handshake is needed. Both client and server sides are
affected when processing peer Certificate messages. The vulnerability was introduced in OTP-23.2.
Affected/Unaffected Versions
A version larger than or equal to one of the listed patched versions is unaffected; otherwise, a version that satisfies an expression listed under affected versions is affected, and if it does not, it is unaffected.
The documentation of the new OTP version scheme describes how versions should be compared. Note that versions used prior to OTP 17.0, when the new OTP version scheme was introduced, are never listed since it is not well defined how to compare those versions.
The code enabling this was introduced in OTP 23.2.
Workarounds
n/a
Credits
Thanks to Lukas Backström at Erlang Solutions for finding and responsibly disclosing this vulnerability to the Erlang/OTP project.
Impact
A TLS/DTLS peer can crash the remote node by sending a certificate chain containing two mutually cross-signed certificates in unordered form. When the receiving side attempts to build a valid chain path, it enters unbounded recursion between the two certificates (A issues B, B issues A) with no cycle detection or depth limit. The call stack and chain accumulator grow without bound until the process exhausts available memory and the BEAM node crashes. The attack requires only a TCP connection and a partial handshake — no authentication or completed handshake is needed. Both client and server sides are
affected when processing peer Certificate messages. The vulnerability was introduced in OTP-23.2.
Affected/Unaffected Versions
A version larger than or equal to one of the listed patched versions is unaffected; otherwise, a version that satisfies an expression listed under affected versions is affected, and if it does not, it is unaffected.
The documentation of the new OTP version scheme describes how versions should be compared. Note that versions used prior to OTP 17.0, when the new OTP version scheme was introduced, are never listed since it is not well defined how to compare those versions.
The code enabling this was introduced in OTP 23.2.
Workarounds
n/a
Credits
Thanks to Lukas Backström at Erlang Solutions for finding and responsibly disclosing this vulnerability to the Erlang/OTP project.