PT-2026-109284 · Riot-Os · Riot
CVE-2026-107838
·
Published
2026-10-09
·
Updated
2026-10-09
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. From version 2023.07 through version 2026.07, nanocoap fileserver callers in sys/net/application layer/nanocoap/fileserver.c ignore a failure returned by resp init() when coap build reply() cannot fit a response header into the response buffer. A remote client can send a CoAP request with a sufficiently large extended token when nanocoap token ext is enabled, causing response initialization to fail while get file() or get directory() continues with stale response state. The path then reaches calc szx2() and its pdu->payload len > reserve assertion, terminating the affected service or device task. No fixed release is available as of this review.
Fix
Assertion Failure
Unchecked Return Value
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Riot