PT-2026-109284 · Riot-Os · Riot

CVE-2026-107838

·

Publicado

2026-10-09

·

Atualizado

2026-10-09

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. From version 2023.07 through version 2026.07, nanocoap fileserver callers in sys/net/application layer/nanocoap/fileserver.c ignore a failure returned by resp init() when coap build reply() cannot fit a response header into the response buffer. A remote client can send a CoAP request with a sufficiently large extended token when nanocoap token ext is enabled, causing response initialization to fail while get file() or get directory() continues with stale response state. The path then reaches calc szx2() and its pdu->payload len > reserve assertion, terminating the affected service or device task. No fixed release is available as of this review.

Correção

Assertion Failure

Unchecked Return Value

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-107838

Produtos afetados

Riot