A remote client can send a CoAP request with a sufficiently large extended token when nanocoap_token_ext is enabled, causing response initialization to fail while _get_file() or _get_directory() continues with stale response state. The vulnerability affects RIOT, an open-source microcontroller operating system used in IoT devices and embedded systems, leading to a reachable assertion and potential denial [truncated]
A vulnerability in RIOT OS 6LoWPAN SFF Fragment Handling allows remote attackers to potentially disclose memory and crash the network stack. The issue arises from the _receive() function in sys/net/gnrc/network_layer/sixlowpan/gnrc_sixlowpan.c, which can route an undersized packet into SFF fragment handling after only a minimal payload check. This can lead to an out-of-bounds read, potentially disclosing [truncated]
RIOT's nanoCoAP client is vulnerable to a buffer underflow when handling Block2 responses with inconsistent server-controlled block sizes. A malicious CoAP server can cause the client to crash, leading to denial of service and potential exposure of adjacent memory. The vulnerability is caused by the nanoCoAP client function nanocoap_sock_get_slice() in sys/net/application_layer/nanocoap/sock.c, which acce [truncated]