Stack-based buffer overflow in the ipv6addrfromstr function in sys/net/networklayer/ipv6/addr/ipv6addrfrom_str.c in RIOT prior to 2017-04-25 allows local attackers, and potentially remote attackers, to cause a denial of service or possibly have unspecified other impact via a malformed IPv6 address.