CVE-2026-107836
Received Received - Intake

RIOT OS CoAP Client Buffer Underflow Vulnerability

Vulnerability report for CVE-2026-107836, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: GitHub, Inc.

Description

RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, the nanoCoAP client function nanocoap_sock_get_slice() in sys/net/application_layer/nanocoap/sock.c accepts a Block2 response when _block_cb() sees the expected block number without also verifying that the server-controlled szx and derived offset match the requested block geometry. A malicious CoAP server can return the expected block number with a larger block size, causing the derived offset to exceed the client slice offset and making ctx->offset - offset underflow in _2buf_slice(). The resulting buffer-relative calculation can read before the payload buffer and crash the client, causing denial of service and potentially exposing adjacent memory. No fixed release is available as of this review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
RIOT-OS RIOT <= 2026.07

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-191 The product subtracts one value from another, such that the result is less than the minimum allowable integer value, which produces a value that is not equal to the correct result.
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects RIOT-OS's nanoCoAP client in versions 2026.07 and earlier. It occurs during CoAP Block2 responses when the client only checks the block number but not the server-controlled block size (szx). A malicious server can return the expected block number with a larger block size, causing an offset miscalculation. This leads to an integer underflow in _2buf_slice(), resulting in a buffer read before the payload buffer, crashing the client or exposing adjacent memory.

Detection Guidance

To detect this vulnerability, monitor CoAP traffic for malformed Block2 responses where the server returns an unexpected block size (szx) or offset. Use Wireshark to capture and analyze CoAP packets, checking for inconsistencies between requested and returned block sizes. Enable debug logs in RIOT-OS to track blockwise transfer errors in sys/net/application_layer/nanocoap/sock.c.

Impact Analysis

This vulnerability can cause denial of service by crashing the RIOT-OS device running the vulnerable nanoCoAP client. It may also expose adjacent memory, potentially leaking sensitive data. Systems relying on CoAP for communication with untrusted servers are at risk if they use affected RIOT-OS versions.

Compliance Impact

This vulnerability could impact compliance by causing service disruptions (denial of service) or unauthorized memory exposure, potentially violating data integrity and confidentiality requirements in GDPR or HIPAA. Affected systems handling sensitive data must address this to maintain compliance.

Mitigation Strategies

Apply the patch from commit 49b894cbe091510093273b98d92c4a17167d6839 to validate server-returned block sizes and offsets before processing. Temporarily disable CoAP Block2 transfers if patches are unavailable. Monitor network traffic for suspicious CoAP responses and update RIOT-OS to the latest version once fixes are released.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107836. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart