Logo
vulnerabilityCVE-2026-29013
Name
CVE-2026-29013
Source
NVD ( link)Debian ( link)
Description
libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in src/oscore/oscore_cbor.c relies solely on assert() for bounds checking, which is removed in release builds compiled with NDEBUG. Attackers can send crafted CoAP requests with malformed OSCORE options or responses during OSCORE negotiation to trigger out-of-bounds reads during CBOR parsing and potentially cause out-of-bounds reads through integer wraparound in allocation size computation.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libcoap
Exploitable

Vulnerability Ratings#


8.8
CVSSv4
9.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
4.3.5a
Exploitable
buildroot
master
4.3.5b
Not Affected
openwrt
openwrt-25.12
4.3.0-r2
Exploitable
yocto
master
4.3.5b
Not Affected
yocto
scarthgap
4.3.4
Exploitable