IPv6 Fragmentation Vulnerability in RIOT Operating System by RIOT OS
CVE-2025-66647
What is CVE-2025-66647?
A vulnerability has been identified in the IPv6 fragmentation reassembly implementation of RIOT OS v2025.07. The issue arises due to a lack of size checks when copying the contents of the first fragment into the reassembly buffer, allowing an attacker to create a small reassembly buffer. An attacker can exploit this flaw by sending a shorter fragment with offset=0, potentially resulting in buffer overflow and subsequent memory corruption. This vulnerability could lead to further exploitation avenues, such as remote code execution, making it essential for users employing the gnrc_ipv6_ext_frag module to upgrade to version 2025.10, which addresses this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
RIOT < 2025.10
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
