RIOT 是一个面向物联网设备及其他嵌入式系统的开源微控制器操作系统。在 2026.07 版本及更早版本中,位于 sys/net/application_layer/nanocoap/sock.c 文件中的 nanoCoAP 客户端函数 nanocoap_sock_get_slice() 存在安全漏洞:当 _block_cb() 检测到预期的块编号时,该函数会接受 Block2 响应,但未同时验证由服务器控制的 szx 参数及由此计算出的偏移量是否与请求的块几何结构相匹配。攻击者可通过恶意 CoAP 服务器返回期望
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107837 | 8.2 HIGH | RIOT: Out-of-Bounds Read in RIOT OS 6LoWPAN SFF Fragment Handling |
| CVE-2026-107838 | 7.5 HIGH | RIOT: nanocoap_fileserver ignores response initialization failure, leading to reachable as |
No comments yet