Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107836— RIOT: nanoCoAP Block2 client slice handling underflows on inconsistent server-controlled block size

Quick assessment

Affected
RIOT-OS RIOT
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

RIOT 是一个面向物联网设备及其他嵌入式系统的开源微控制器操作系统。在 2026.07 版本及更早版本中,位于 sys/net/application_layer/nanocoap/sock.c 文件中的 nanoCoAP 客户端函数 nanocoap_sock_get_slice() 存在安全漏洞:当 _block_cb() 检测到预期的块编号时,该函数会接受 Block2 响应,但未同时验证由服务器控制的 szx 参数及由此计算出的偏移量是否与请求的块几何结构相匹配。攻击者可通过恶意 CoAP 服务器返回期望

CVSS 7.1 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
RIOT-OS RIOT <= 2026.07 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107836

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
RIOT: nanoCoAP Block2 client slice handling underflows on inconsistent server-controlled block size
Source: CVE Program / CVE List V5
Vulnerability Description
RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, the nanoCoAP client function nanocoap_sock_get_slice() in sys/net/application_layer/nanocoap/sock.c accepts a Block2 response when _block_cb() sees the expected block number without also verifying that the server-controlled szx and derived offset match the requested block geometry. A malicious CoAP server can return the expected block number with a larger block size, causing the derived offset to exceed the client slice offset and making ctx->offset - offset underflow in _2buf_slice(). The resulting buffer-relative calculation can read before the payload buffer and crash the client, causing denial of service and potentially exposing adjacent memory. No fixed release is available as of this review.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
RIOT-OS RIOT <= 2026.07 -

II. Public POCs for CVE-2026-107836

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107836

请登录查看更多情报信息。

Other References for CVE-2026-107836 (3)

Same Patch Batch · RIOT-OS · 2026-10-09 · 3 CVEs total

CVE-2026-107837 8.2 HIGH RIOT: Out-of-Bounds Read in RIOT OS 6LoWPAN SFF Fragment Handling
CVE-2026-107838 7.5 HIGH RIOT: nanocoap_fileserver ignores response initialization failure, leading to reachable as

IV. Related Vulnerabilities

V. Comments for CVE-2026-107836

No comments yet


Leave a comment