CVE-2026-107838: RIOT: nanocoap_fileserver ignores response initialization failure, leading to reachable assertion

Published Oct 9, 2026
·
Updated

RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. From version 2023.07 through version 2026.07, nanocoapfileserver callers in sys/net/applicationlayer/nanocoap/fileserver.c ignore a failure returned by respinit() when coapbuildreply() cannot fit a response header into the response buffer. A remote client can send a CoAP request with a sufficiently large extended token when nanocoaptokenext is enabled, causing response initialization to fail while getfile() or getdirectory() continues with stale response state. The path then reaches calcszx2() and its pdu->payloadlen > reserve assertion, terminating the affected service or device task. No fixed release is available as of this review.

Affected Software

1 affected component
RIOT RIOT>=2023.07<=2026.07

Event History

Oct 9, 2026
CVE Published
via MITRE·05:55 PM
Data Sourced
via MITRE·05:55 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to this denial-of-service condition?

Deployments running RIOT versions 2023.07 through 2026.07 are affected when they use nanocoap_fileserver and have nanocoap_token_ext enabled. The issue is reachable remotely through CoAP requests.

2

What does an attacker need to send to trigger the failure?

An unauthenticated remote client needs to send a CoAP request containing a sufficiently large extended token. This causes the response header not to fit in the response buffer, after which stale response state can reach an assertion.

3

What is the operational impact of successful exploitation?

The assertion terminates the affected service or device task, resulting in a denial of service. The provided data does not indicate confidentiality or integrity impact.

4

What can be done if an update is not available?

No fixed release is available as of the review. Reduce exposure by disabling nanocoap_token_ext where feasible or preventing untrusted remote clients from reaching the affected CoAP fileserver.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203