Denial of Service Vulnerability in RIOT OS for IoT Devices
CVE-2026-107836
7.1HIGH
What is CVE-2026-107836?
RIOT OS, an open-source operating system for Internet of Things (IoT) devices, has a vulnerability in its nanoCoAP client function, specifically the nanocoap_sock_get_slice(). In versions 2026.07 and earlier, this function improperly validates the server-controlled size and derived offset against the expected block number. A malicious CoAP server can manipulate this validation, leading to a denial of service condition by crashing the client. It risks exposing adjacent memory areas due to improper buffer calculations, which can compromise the stability of IoT applications without a fixed release to remediate the issue.
Affected Version(s)
RIOT <= 2026.07
