IPv6 Fragmentation Vulnerability in RIOT Operating System by RIOT OS
CVE-2025-66647

1.7LOW

Key Information:

Vendor

Riot-os

Status
Vendor
CVE Published:
17 December 2025

What is CVE-2025-66647?

A vulnerability has been identified in the IPv6 fragmentation reassembly implementation of RIOT OS v2025.07. The issue arises due to a lack of size checks when copying the contents of the first fragment into the reassembly buffer, allowing an attacker to create a small reassembly buffer. An attacker can exploit this flaw by sending a shorter fragment with offset=0, potentially resulting in buffer overflow and subsequent memory corruption. This vulnerability could lead to further exploitation avenues, such as remote code execution, making it essential for users employing the gnrc_ipv6_ext_frag module to upgrade to version 2025.10, which addresses this issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

RIOT < 2025.10

References

CVSS V4

Score:
1.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.