---
id: CVE-2026-107836
title: >-
  RIOT is an open-source microcontroller operating system designed for Internet
  of Things devices and other embedded systems
summary: >-
  RIOT is an open-source microcontroller operating system designed for Internet
  of Things devices and other embedded systems. In 2026.07 and earlier, the
  nanoCoAP client function nanocoap_sock_get_slice() in
  sys/net/application_layer/nanoc…
severity: none
cwe:
  - CWE-125
  - CWE-191
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T18:17:05.310'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107836'
references:
  - url: >-
      https://github.com/RIOT-OS/RIOT/commit/49b894cbe091510093273b98d92c4a17167d6839
    label: security-advisories@github.com
  - url: 'https://github.com/RIOT-OS/RIOT/pull/22518'
    label: security-advisories@github.com
  - url: 'https://github.com/RIOT-OS/RIOT/security/advisories/GHSA-x924-p5fq-26pc'
    label: security-advisories@github.com
tags:
  - nvd
ingestedAt: '2026-10-09T19:09:33.755Z'
---

## Overview

RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, the nanoCoAP client function nanocoap_sock_get_slice() in sys/net/application_layer/nanocoap/sock.c accepts a Block2 response when _block_cb() sees the expected block number without also verifying that the server-controlled szx and derived offset match the requested block geometry. A malicious CoAP server can return the expected block number with a larger block size, causing the derived offset to exceed the client slice offset and making ctx->offset - offset underflow in _2buf_slice(). The resulting buffer-relative calculation can read before the payload buffer and crash the client, causing denial of service and potentially exposing adjacent memory. No fixed release is available as of this review.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
