CVE-2026-107838: RIOT: nanocoap_fileserver ignores response initialization failure, leading to reachable assertion
RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. From version 2023.07 through version 2026.07, nanocoapfileserver callers in sys/net/applicationlayer/nanocoap/fileserver.c ignore a failure returned by respinit() when coapbuildreply() cannot fit a response header into the response buffer. A remote client can send a CoAP request with a sufficiently large extended token when nanocoaptokenext is enabled, causing response initialization to fail while getfile() or getdirectory() continues with stale response state. The path then reaches calcszx2() and its pdu->payloadlen > reserve assertion, terminating the affected service or device task. No fixed release is available as of this review.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this denial-of-service condition?
Deployments running RIOT versions 2023.07 through 2026.07 are affected when they use nanocoap_fileserver and have nanocoap_token_ext enabled. The issue is reachable remotely through CoAP requests.
What does an attacker need to send to trigger the failure?
An unauthenticated remote client needs to send a CoAP request containing a sufficiently large extended token. This causes the response header not to fit in the response buffer, after which stale response state can reach an assertion.
What is the operational impact of successful exploitation?
The assertion terminates the affected service or device task, resulting in a denial of service. The provided data does not indicate confidentiality or integrity impact.
What can be done if an update is not available?
No fixed release is available as of the review. Reduce exposure by disabling nanocoap_token_ext where feasible or preventing untrusted remote clients from reaching the affected CoAP fileserver.