Description
RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. From version 2023.07 through version 2026.07, nanocoap_fileserver callers in sys/net/application_layer/nanocoap/fileserver.c ignore a failure returned by _resp_init() when coap_build_reply() cannot fit a response header into the response buffer. A remote client can send a CoAP request with a sufficiently large extended token when nanocoap_token_ext is enabled, causing response initialization to fail while _get_file() or _get_directory() continues with stale response state. The path then reaches _calc_szx2() and its pdu->payload_len > reserve assertion, terminating the affected service or device task. No fixed release is available as of this review.
Published: 2026-10-09
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Monitor
AI Analysis

Impact

A fault in the RIOT nanocoap_fileserver causes it to ignore errors returned by response initialization when a CoAP request contains an oversized extended token. The bug leads to a stale response buffer and triggers an assertion during size calculation, terminating the service or device task. This flaw is a high‑severity remote denial of service that can be exercised over the network.

Affected Systems

The vulnerability affects RIOT‑OS releases from 2023.07 through 2026.07. It is present in all embedded devices that run these RIOT versions and have the nanocoap_fileserver component enabled, especially those configured to accept extended tokens.

Risk and Exploitability

The CVSS score of 7.5 indicates high impact, while no EPSS data is currently available and the flaw is not listed in the CISA KEV catalog. An attacker can trigger it via a crafted CoAP request sent from the network, causing the target to crash. With no patch yet released, the risk remains high until official remediation arrives.

Generated by OpenCVE AI on October 9, 2026 at 19:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest RIOT update once the flaw is fixed.
  • Disable or limit the nanocoap_token_ext option so that oversized CoAP tokens cannot be processed.
  • Configure a watchdog or supervisor to restart the affected task or device after an assertion‑driven crash.

Generated by OpenCVE AI on October 9, 2026 at 19:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. From version 2023.07 through version 2026.07, nanocoap_fileserver callers in sys/net/application_layer/nanocoap/fileserver.c ignore a failure returned by _resp_init() when coap_build_reply() cannot fit a response header into the response buffer. A remote client can send a CoAP request with a sufficiently large extended token when nanocoap_token_ext is enabled, causing response initialization to fail while _get_file() or _get_directory() continues with stale response state. The path then reaches _calc_szx2() and its pdu->payload_len > reserve assertion, terminating the affected service or device task. No fixed release is available as of this review.
Title RIOT: nanocoap_fileserver ignores response initialization failure, leading to reachable assertion
Weaknesses CWE-252
CWE-617
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-09T17:55:34.670Z

Reserved: 2026-10-08T22:34:49.290Z

Link: CVE-2026-107838

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T18:17:05.640

Modified: 2026-10-09T18:17:05.640

Link: CVE-2026-107838

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T19:30:11Z

Weaknesses