---
id: CVE-2026-5855
title: >-
  Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in
  os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length
  argument and reads up to six bytes from the input buffer with no bounds check
summary: >-
  Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in
  os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length
  argument and reads up to six bytes from the input buffer with no bounds check.
  The caller in lwm2m-engine.c iterate…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-125
published: '2026-08-06'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T20:21:01.047'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-5855'
references:
  - url: 'https://github.com/contiki-ng/contiki-ng'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/contiki-ng/contiki-ng/commit/f1673b5766d4d4d514cefb8a0350f43653574997
    label: disclosure@vulncheck.com
  - url: 'https://github.com/contiki-ng/contiki-ng/pull/3165'
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00537
epssPercentile: 0.44203
ingestedAt: '2026-09-16T21:05:36.835Z'
---

## Overview

Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to six bytes from the input buffer with no bounds check. The caller in lwm2m-engine.c iterates while there is at least one byte remaining, so a crafted CoAP WRITE to any LwM2M endpoint whose final TLV supplies exactly one byte triggers up to five out-of-bounds reads of heap memory adjacent to the CoAP input buffer, disclosing memory contents (including key material and peer addresses) through the parsed tlv->id, tlv->length, and tlv->value fields. Corrupted tlv_len derived from the out-of-bounds memory further corrupts the caller's parse offset. In LwM2M NoSec mode, the default for constrained devices, no authentication is required.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
