{"id":"CVE-2026-5855","title":"Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no bounds check","summary":"Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no bounds check. The caller in lwm2m-engine.c iterate…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-125"],"published":"2026-08-06","updated":"2026-09-16","sourceUpdated":"2026-09-16T20:21:01.047","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-5855","references":[{"url":"https://github.com/contiki-ng/contiki-ng","label":"disclosure@vulncheck.com"},{"url":"https://github.com/contiki-ng/contiki-ng/commit/f1673b5766d4d4d514cefb8a0350f43653574997","label":"disclosure@vulncheck.com"},{"url":"https://github.com/contiki-ng/contiki-ng/pull/3165","label":"disclosure@vulncheck.com"}],"tags":["nvd"],"epss":0.00537,"epssPercentile":0.4418,"ingestedAt":"2026-09-16T21:05:36.835Z","slug":"CVE-2026-5855","body":"## Overview\n\nContiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no bounds check. The caller in lwm2m-engine.c iterates while there is at least one byte remaining, so a crafted CoAP WRITE to any LwM2M endpoint whose final TLV supplies exactly one byte triggers up to five out-of-bounds reads of heap memory adjacent to the CoAP input buffer, disclosing memory contents (including key material and peer addresses) through the parsed tlv->id, tlv->length, and tlv->value fields. Corrupted tlv_len derived from the out-of-bounds memory further corrupts the caller's parse offset. In LwM2M NoSec mode, the default for constrained devices, no authentication is required.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}