๐Ÿ” CVE Alert

CVE-2026-107836

UNKNOWN 0.0

RIOT: nanoCoAP Block2 client slice handling underflows on inconsistent server-controlled block size

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, the nanoCoAP client function nanocoap_sock_get_slice() in sys/net/application_layer/nanocoap/sock.c accepts a Block2 response when _block_cb() sees the expected block number without also verifying that the server-controlled szx and derived offset match the requested block geometry. A malicious CoAP server can return the expected block number with a larger block size, causing the derived offset to exceed the client slice offset and making ctx->offset - offset underflow in _2buf_slice(). The resulting buffer-relative calculation can read before the payload buffer and crash the client, causing denial of service and potentially exposing adjacent memory. No fixed release is available as of this review.

CWE CWE-125 CWE-191
Vendor riot-os
Product riot
Published Oct 9, 2026
Last Updated Oct 9, 2026
Stay Ahead of the Next One

Get instant alerts for riot-os riot

Be the first to know when new unknown vulnerabilities affecting riot-os riot are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

RIOT-OS / RIOT
<= 2026.07

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/RIOT-OS/RIOT/security/advisories/GHSA-x924-p5fq-26pc github.com: https://github.com/RIOT-OS/RIOT/pull/22518 github.com: https://github.com/RIOT-OS/RIOT/commit/49b894cbe091510093273b98d92c4a17167d6839