No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 09 Oct 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Riot-os
Riot-os riot |
|
| Vendors & Products |
Riot-os
Riot-os riot |
Fri, 09 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Oct 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, the nanoCoAP client function nanocoap_sock_get_slice() in sys/net/application_layer/nanocoap/sock.c accepts a Block2 response when _block_cb() sees the expected block number without also verifying that the server-controlled szx and derived offset match the requested block geometry. A malicious CoAP server can return the expected block number with a larger block size, causing the derived offset to exceed the client slice offset and making ctx->offset - offset underflow in _2buf_slice(). The resulting buffer-relative calculation can read before the payload buffer and crash the client, causing denial of service and potentially exposing adjacent memory. No fixed release is available as of this review. | |
| Title | RIOT: nanoCoAP Block2 client slice handling underflows on inconsistent server-controlled block size | |
| Weaknesses | CWE-125 CWE-191 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-09T18:00:37.637Z
Reserved: 2026-10-08T22:34:49.289Z
Link: CVE-2026-107836
Updated: 2026-10-09T18:00:25.137Z
Status : Received
Published: 2026-10-09T18:17:05.310
Modified: 2026-10-09T18:17:05.310
Link: CVE-2026-107836
No data.
OpenCVE Enrichment
Updated: 2026-10-09T19:30:10Z