Description
RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, _receive() in sys/net/gnrc/network_layer/sixlowpan/gnrc_sixlowpan.c can route an undersized packet into SFF fragment handling after only a minimal payload check. The code then interprets the packet as a sixlowpan_frag_t or larger fragment header without verifying that the packet snip contains the required bytes. A remote attacker can send a malformed 6LoWPAN fragment that causes gnrc_sixlowpan_frag_recv() to read beyond the packet buffer, potentially disclosing memory and crashing the network stack. No fixed repository release is available as of this review.
Published: 2026-10-09
Score: 8.2 High
EPSS: n/a
KEV: No
Impact: Memory Disclosure
Action: Assess Impact
AI Analysis

Impact

A remote attacker can craft a malformed 6LoWPAN fragment that reaches the gnrc_sixlowpan_frag_recv() routine in RIOT OS. The routine interprets the packet as a sixlowpan_frag_t header without verifying that the payload contains the required bytes, leading to an out‑of‑bounds read (CWE‑125). The resulting read can expose arbitrary memory contents to the attacker and may also cause a crash of the network stack, effectively creating a denial‑of‑service vector. The primary security impact is the potential disclosure of sensitive memory data and interruption of network operation.

Affected Systems

RIOT OS 6LoWPAN stacks deployed in versions released in or before 2026.07 are affected. The vulnerability exists within the sys/net/gnrc/network_layer/sixlowpan/gnrc_sixlowpan.c source file of the RIOT project, impacting embedded devices running the microcontroller OS for IoT applications. No specific sub‑product or version beyond the 2026.07 release date is identified, but any build derived from these releases is potentially vulnerable.

Risk and Exploitability

The CVSS base score of 8.2 indicates a high‑severity weakness. Although the EPSS score is not available, the lack of a publicly fixed version means the exploitation probability remains high for systems still running vulnerable code. The vulnerability can be triggered remotely by an attacker who can inject a crafted 6LoWPAN fragment across an untrusted network segment. No official patch has been released at the time of this analysis, and the issue is not listed in the CISA KEV catalog. Consequently, the threat remains significant for devices that rely on the current RIOT OS release and are exposed to untrusted 6LoWPAN traffic.

Generated by OpenCVE AI on October 9, 2026 at 19:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply a network filter or firewall rule to detect and block malformed 6LoWPAN fragments before they reach the RIOT device.
  • When a fix is released, upgrade the RIOT OS source to the latest stable version, recompile the firmware, and reinstall it on all affected devices.
  • Until a patch is available, limit exposure by disabling SFF fragmentation features or routing traffic through a gateway that sanitizes or rejects malformed fragments.

Generated by OpenCVE AI on October 9, 2026 at 19:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Riot-os
Riot-os riot
Vendors & Products Riot-os
Riot-os riot

Fri, 09 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. In 2026.07 and earlier, _receive() in sys/net/gnrc/network_layer/sixlowpan/gnrc_sixlowpan.c can route an undersized packet into SFF fragment handling after only a minimal payload check. The code then interprets the packet as a sixlowpan_frag_t or larger fragment header without verifying that the packet snip contains the required bytes. A remote attacker can send a malformed 6LoWPAN fragment that causes gnrc_sixlowpan_frag_recv() to read beyond the packet buffer, potentially disclosing memory and crashing the network stack. No fixed repository release is available as of this review.
Title RIOT: Out-of-Bounds Read in RIOT OS 6LoWPAN SFF Fragment Handling
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T17:53:47.707Z

Reserved: 2026-10-08T22:34:49.289Z

Link: CVE-2026-107837

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T18:17:05.483

Modified: 2026-10-09T18:17:05.483

Link: CVE-2026-107837

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T19:30:11Z

Weaknesses