CVE-2026-107836
RIOT: nanoCoAP Block2 client slice handling underflows on inconsistent server-controlled block size
RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, the nanoCoAP client function nanocoap_sock_get_slice() in sys/net/application_layer/nanocoap/sock.c accepts a Block2 response when _block_cb() sees the expected block number without also verifying that the server-controlled szx and derived offset match the requested block geometry. A malicious CoAP server can return the expected block number with a larger block size, causing the derived offset to exceed the client slice offset and making ctx->offset - offset underflow in _2buf_slice(). The resulting buffer-relative calculation can read before the payload buffer and crash the client, causing denial of service and potentially exposing adjacent memory. No fixed release is available as of this review.
| CWE | CWE-125 CWE-191 |
| Vendor | riot-os |
| Product | riot |
| Published | Oct 9, 2026 |
| Last Updated | Oct 9, 2026 |
Get instant alerts for riot-os riot
Be the first to know when new unknown vulnerabilities affecting riot-os riot are published โ delivered to Slack, Telegram or Discord.