CVE-2026-107838

Source
https://cve.org/CVERecord?id=CVE-2026-107838
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107838.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107838
Aliases
  • GHSA-39j3-3v73-5mj2
Published
2026-10-09T17:55:34Z
Modified
2026-10-11T07:05:49Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
RIOT: nanocoap_fileserver ignores response initialization failure, leading to reachable assertion
Details

RIOT is an open-source microcontroller operating system designed for Internet of Things devices and other embedded systems. From version 2023.07 through version 2026.07, nanocoap_fileserver callers in sys/net/application_layer/nanocoap/fileserver.c ignore a failure returned by _resp_init() when coap_build_reply() cannot fit a response header into the response buffer. A remote client can send a CoAP request with a sufficiently large extended token when nanocoap_token_ext is enabled, causing response initialization to fail while _get_file() or _get_directory() continues with stale response state. The path then reaches _calc_szx2() and its pdu->payload_len > reserve assertion, terminating the affected service or device task. No fixed release is available as of this review.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-252",
        "CWE-617"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107838.json"
}
References

Affected packages

Git / github.com/riot-os/riot

Affected ranges

Type
GIT
Repo
https://github.com/riot-os/riot
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2023.07"
        },
        {
            "fixed": "2026.07"
        }
    ],
    "source": [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

2023.*
2023.04-RC1
2023.07-RC1
2023.07-devel
2023.10-RC1
2023.10-devel
2024.*
2024.01-RC1
2024.01-devel
2024.04
2024.04-RC1
2024.04-devel
2024.07-RC1
2024.07-devel
2024.10-RC1
2024.10-devel
2025.*
2025.01-RC1
2025.01-devel
2025.04-RC1
2025.04-devel
2025.07-RC1
2025.07-devel
2025.10-RC1
2025.10-devel
2026.*
2026.01-RC1
2026.01-devel
2026.04-devel

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107838.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "171507221497450670567383896486461591823",
                "184222878039072624379591828366831829964",
                "244529858853978079423892502861736251244",
                "229861985934956762961893705134281501212",
                "99991400939048286714452585311656272165",
                "20982551879899120631395534511945575343",
                "36445335840178027683593728941929430566",
                "57603119724233125385704002323619310573",
                "158265367178564601914102126394761431642",
                "61875553451868952054840311218476251695",
                "247955484745545944234616396512263699995",
                "164995089561970739279645862456886029896",
                "272459023698889316599739721912149776267",
                "123779484895205659669835385967820346918",
                "116824370878028326268113191768354416517",
                "255715907276742379817709658708132878388",
                "79614774512381930966131092153987254225",
                "146766668663944246413124398172786046504",
                "61586085463865408319706340935638508243",
                "55105503275451565111573641831781919354",
                "212607372852184917526116510251012259399",
                "283591168067188050408647847092204416066",
                "55196908150625645248921882282857822065",
                "44244223599788185734379947159049266752",
                "221221649292275267084490068584598578441",
                "33879318618965827059104423991556080247",
                "13152017990115001845208375755953965654",
                "246191985437730745066658114537660807138",
                "218016648420088833521623090492194545058",
                "209157724021466752027725639418832171574",
                "110134655871889370691933888045416497473",
                "43367216457861263520870247183542063936",
                "325607893680895168219806812952758365252",
                "158230864287806813985469762761555400627",
                "61586085463865408319706340935638508243",
                "55105503275451565111573641831781919354"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107838-031515e5",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/riot-os/riot/commit/d3a47289c58d108575a19e623e4d3f647659e743",
        "target": {
            "file": "sys/net/application_layer/nanocoap/fileserver.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "410120153769142573750678630796507626",
            "length": 757
        },
        "id": "CVE-2026-107838-0aca4b32",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/riot-os/riot/commit/d3a47289c58d108575a19e623e4d3f647659e743",
        "target": {
            "file": "sys/net/application_layer/nanocoap/fileserver.c",
            "function": "_put_directory"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "197246149766307422549953924345109508386",
            "length": 790
        },
        "id": "CVE-2026-107838-16aa3e67",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/riot-os/riot/commit/d3a47289c58d108575a19e623e4d3f647659e743",
        "target": {
            "file": "sys/net/application_layer/nanocoap/fileserver.c",
            "function": "_delete_file"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "251533180506767637427407042197260998372",
            "length": 2359
        },
        "id": "CVE-2026-107838-7d668125",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/riot-os/riot/commit/d3a47289c58d108575a19e623e4d3f647659e743",
        "target": {
            "file": "sys/net/application_layer/nanocoap/fileserver.c",
            "function": "_get_file"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "184441348458783064992535294274914401886",
            "length": 1871
        },
        "id": "CVE-2026-107838-bf06ad21",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/riot-os/riot/commit/d3a47289c58d108575a19e623e4d3f647659e743",
        "target": {
            "file": "sys/net/application_layer/nanocoap/fileserver.c",
            "function": "_get_directory"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "265169051995314361809539259181108406848",
            "length": 2928
        },
        "id": "CVE-2026-107838-de28f12e",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/riot-os/riot/commit/d3a47289c58d108575a19e623e4d3f647659e743",
        "target": {
            "file": "sys/net/application_layer/nanocoap/fileserver.c",
            "function": "_put_file"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "158857300323127895846261340431503356777",
            "length": 764
        },
        "id": "CVE-2026-107838-e82b5707",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/riot-os/riot/commit/d3a47289c58d108575a19e623e4d3f647659e743",
        "target": {
            "file": "sys/net/application_layer/nanocoap/fileserver.c",
            "function": "_delete_directory"
        }
    }
]
vanir_signatures_modified
"2026-10-11T07:05:49Z"