Impact
A remote attacker can craft a malformed 6LoWPAN fragment that reaches the gnrc_sixlowpan_frag_recv() routine in RIOT OS. The routine interprets the packet as a sixlowpan_frag_t header without verifying that the payload contains the required bytes, leading to an out‑of‑bounds read (CWE‑125). The resulting read can expose arbitrary memory contents to the attacker and may also cause a crash of the network stack, effectively creating a denial‑of‑service vector. The primary security impact is the potential disclosure of sensitive memory data and interruption of network operation.
Affected Systems
RIOT OS 6LoWPAN stacks deployed in versions released in or before 2026.07 are affected. The vulnerability exists within the sys/net/gnrc/network_layer/sixlowpan/gnrc_sixlowpan.c source file of the RIOT project, impacting embedded devices running the microcontroller OS for IoT applications. No specific sub‑product or version beyond the 2026.07 release date is identified, but any build derived from these releases is potentially vulnerable.
Risk and Exploitability
The CVSS base score of 8.2 indicates a high‑severity weakness. Although the EPSS score is not available, the lack of a publicly fixed version means the exploitation probability remains high for systems still running vulnerable code. The vulnerability can be triggered remotely by an attacker who can inject a crafted 6LoWPAN fragment across an untrusted network segment. No official patch has been released at the time of this analysis, and the issue is not listed in the CISA KEV catalog. Consequently, the threat remains significant for devices that rely on the current RIOT OS release and are exposed to untrusted 6LoWPAN traffic.
OpenCVE Enrichment