VendorsRIOT-OSriotany version
Vulnerabilities

RIOT-OS RIOT any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

27CVEs
CVE-2019-1000006
RIOT RIOT-OS version after commit 7af03ab624db0412c727eed9ab7630a5282e2fd3 contains a Buffer Overflow vulnerability in sock_dns, an implementation of the DNS protocol utilizing the RIOT sock API that can result in Remote code executing. This attack appears to be exploitable via network connectivity.
Published 2019-02-04 · Modified
9.8EPSS 0.016
CVE-2024-32017
Buffer overflows in RIOT
Published 2024-05-01 · Analyzed
9.8EPSS 0.015
CVE-2023-33975
RIOT-OS vulnerable to Out of Bounds Write in _rbuf_add
Published 2023-05-30 · Modified
9.8EPSS 0.015
CVE-2023-24819
RIOT-OS vulnerable to Buffer Overflow during IPHC receive
Published 2023-04-24 · Modified
9.8EPSS 0.010
CVE-2023-24823
RIOT-OS vulnerable to Packet Type Confusion during IPHC send
Published 2023-04-24 · Modified
9.8EPSS 0.010
CVE-2025-66647
RIOT OS has buffer overflow in gnrc_ipv6_ext_frag_reass
Published 2025-12-17 · Analyzed
9.8EPSS 0.010
CVE-2025-53888
RIOT-OS has an ineffective size check that can lead to buffer overflow in link layer address filter /sys/net/link_layer/l2filter/l2filter.c
Published 2025-07-18 · Analyzed
9.8EPSS 0.007
CVE-2026-27703
RIOT has an Out-of-Bounds Write in nanoCoAP Handler
Published 2026-03-11 · Analyzed
9.8EPSS 0.006
CVE-2026-22214
RIOT OS <= 2026.01-devel-317 Stack-Based Buffer Overflow in ethos Serial Frame Parser
Published 2026-01-12 · Analyzed
9.8EPSS 0.005
CVE-2026-22213
RIOT OS <= 2026.01-devel-317 Stack-Based Buffer Overflow in tapslip6 Utility
Published 2026-01-12 · Analyzed
9.8EPSS 0.004
CVE-2026-25139
RIOT Vulnerable to Multiple Out-of-Bounds Read When Processing Received 6LoWPAN SFR Fragments
Published 2026-02-04 · Analyzed
9.1EPSS 0.005
CVE-2024-32018
Ineffective size check due to assert() and buffer overflow in RIOT
Published 2024-05-01 · Analyzed
9.0EPSS 0.015
CVE-2024-31225
Lack of size check and buffer overflow in RIOT
Published 2024-05-01 · Analyzed
9.0EPSS 0.013
CVE-2019-15134
RIOT through 2019.07 contains a memory leak in the TCP implementation (gnrc_tcp), allowing an attacker to consume all memory available for network packets and thus effectively stopping all network threads from working. This is related to _receive in sys/net/gnrc/transport_layer/tcp/gnrc_tcp_eventloop.c upon receiving an ACK before a SYN.
Published 2019-08-17 · Modified
7.8EPSS 0.015
CVE-2019-15702
In the TCP implementation (gnrc_tcp) in RIOT through 2019.07, the parser for TCP options does not terminate on all inputs, allowing a denial-of-service, because sys/net/gnrc/transport_layer/tcp/gnrc_tcp_option.c has an infinite loop for an unknown zero-length option.
Published 2019-08-27 · Modified
7.5EPSS 0.014
CVE-2023-24818
RIOT-OS vulnerable to null pointer dereference during fragment forwarding
Published 2023-04-24 · Modified
7.5EPSS 0.012
CVE-2023-33973
RIOT-OS vulnerable to NULL pointer dereference during NHC encoding
Published 2023-05-30 · Modified
7.5EPSS 0.010
CVE-2023-24825
RIOT-OS vulnerable to NULL pointer dereference in gnrc_pktbuf_mark
Published 2023-05-30 · Modified
7.5EPSS 0.010
CVE-2023-24822
RIOT-OS vulnerable to Null Pointer dereference during IPHC encoding
Published 2023-04-24 · Modified
7.5EPSS 0.009
CVE-2023-24821
RIOT-OS vulnerable to Integer Underflow during defragmentation
Published 2023-04-24 · Modified
7.5EPSS 0.009
CVE-2023-24820
RIOT-OS vulnerable to Integer Underflow during IPHC receive
Published 2023-04-24 · Modified
7.5EPSS 0.009
CVE-2023-24826
Usage of Uninitialized Timer during forwarding of Fragments with SFR
Published 2023-05-30 · Modified
7.5EPSS 0.008
CVE-2024-52802
RIOT-OS missing dhcpv6_opt_t minimum header length check
Published 2024-11-22 · Analyzed
7.5EPSS 0.008
CVE-2024-53980
Spoofed length byte traps CC2538 in endless loop
Published 2024-11-29 · Analyzed
7.5EPSS 0.008
CVE-2023-33974
RIOT-OS vulnerable to Race Condition in SFR Timeout
Published 2023-05-30 · Modified
7.5EPSS 0.007
CVE-2025-66646
RIOT-OS has NULL pointer dereference in gnrc_ipv6_ext_frag_reass
Published 2025-12-17 · Analyzed
7.5EPSS 0.007
CVE-2023-24817
RIOT-OS vulnerable to Out of Bounds write in routing with SRH
Published 2023-05-30 · Modified
7.5EPSS 0.006