Aller au contenu

Fiche vulnérabilité

CVE-2026-29013 : faille critique libcoap libcoap (CVSS 9.8)

Description

libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in src/oscore/oscore_cbor.c relies solely on assert() for bounds checking, which is removed in release builds compiled with NDEBUG. Attackers can send crafted CoAP requests with malformed OSCORE options or responses during OSCORE negotiation to trigger out-of-bounds reads during CBOR parsing and potentially cause out-of-bounds reads through integer wraparound in allocation size computation.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
17 avr. 2026
Dernière mise à jour
17 juin 2026

Produits concernés

  • libcoap libcoap

Références

Rechercher une autre vulnérabilité dans la base CVE