关键漏洞信息 Vulnerability Title: - RIOT OS <= 2026.01-devel-317 Stack-Based Buffer Overflow in ethos Serial Frame Parser Severity: - Medium Date: - January 12, 2026 Affected Versions: - RIOT OS <= 2026.01-devel-317 CVE ID: - CVE-2026-22214 CWE ID: - CWE-121 Stack-based Buffer Overflow CVSS Score: - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Description: - RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the ethos utility due to missing bounds checking when processing incoming serial frame data. The vulnerability occurs in the function, where incoming frame bytes are appended to a fixed-size stack buffer without verifying that the current write index remains within bounds. An attacker capable of sending crafted serial or TCP-framed input can cause the current write index to exceed the buffer size, resulting in a write past the end of the stack buffer. This condition leads to memory corruption and application crash. References: - Researcher SecLists Disclosure - RIOT OS Webpage - RIOT OS GitHub Repository Credit: - Ron Edgerson