PT-2026-109284 · Riot-Os · Riot

CVE-2026-107838

·

Published

2026-10-09

·

Updated

2026-10-09

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. From version 2023.07 through version 2026.07, nanocoap fileserver callers in sys/net/application layer/nanocoap/fileserver.c ignore a failure returned by resp init() when coap build reply() cannot fit a response header into the response buffer. A remote client can send a CoAP request with a sufficiently large extended token when nanocoap token ext is enabled, causing response initialization to fail while get file() or get directory() continues with stale response state. The path then reaches calc szx2() and its pdu->payload len > reserve assertion, terminating the affected service or device task. No fixed release is available as of this review.

Fix

Assertion Failure

Unchecked Return Value

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107838

Affected Products

Riot