Buffer Overflow Affecting riot-os/riot package, versions [,2025.10)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.95% (59th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-RIOTOSRIOT-14468766
  • published18 Dec 2025
  • disclosed17 Dec 2025
  • creditNils Bernsdorf

Introduced: 17 Dec 2025

CVE-2025-66647  (opens in a new tab)
CWE-120  (opens in a new tab)

How to fix?

Upgrade riot-os/riot to version 2025.10 or higher.

Overview

Affected versions of this package are vulnerable to Buffer Overflow via the gnrc_ipv6_ext_frag_reass function. An attacker can corrupt memory and potentially execute arbitrary code by sending specially crafted IPv6 fragments that exploit the lack of size checks during reassembly. This is only exploitable if the gnrc_ipv6_ext_frag module is included and the attacker can send arbitrary IPv6 packets to the target.

CVSS Base Scores

version 4.0
version 3.1