{"id":"CVE-2026-107836","title":"RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems","summary":"RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, the nanoCoAP client function nanocoap_sock_get_slice() in sys/net/application_layer/nanoc…","severity":"none","cwe":["CWE-125","CWE-191"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T18:17:05.310","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107836","references":[{"url":"https://github.com/RIOT-OS/RIOT/commit/49b894cbe091510093273b98d92c4a17167d6839","label":"security-advisories@github.com"},{"url":"https://github.com/RIOT-OS/RIOT/pull/22518","label":"security-advisories@github.com"},{"url":"https://github.com/RIOT-OS/RIOT/security/advisories/GHSA-x924-p5fq-26pc","label":"security-advisories@github.com"}],"tags":["nvd"],"ingestedAt":"2026-10-09T19:09:33.755Z","slug":"CVE-2026-107836","body":"## Overview\n\nRIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, the nanoCoAP client function nanocoap_sock_get_slice() in sys/net/application_layer/nanocoap/sock.c accepts a Block2 response when _block_cb() sees the expected block number without also verifying that the server-controlled szx and derived offset match the requested block geometry. A malicious CoAP server can return the expected block number with a larger block size, causing the derived offset to exceed the client slice offset and making ctx->offset - offset underflow in _2buf_slice(). The resulting buffer-relative calculation can read before the payload buffer and crash the client, causing denial of service and potentially exposing adjacent memory. No fixed release is available as of this review.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}