Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 21 Jan 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:o:riot-os:riot:*:*:*:*:*:*:*:* cpe:2.3:o:riot-os:riot:2026.01:devel:*:*:*:*:*:* cpe:2.3:o:riot-os:riot:2026.01:rc1:*:*:*:*:*:* |
|
| Metrics |
cvssV3_1
|
Tue, 13 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Jan 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Riot-os
Riot-os riot |
|
| Vendors & Products |
Riot-os
Riot-os riot |
Mon, 12 Jan 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | RIOT OS versions up to and including 2026.01-devel-317 contain a stack-based buffer overflow vulnerability in the ethos utility due to missing bounds checking when processing incoming serial frame data. The vulnerability occurs in the _handle_char() function, where incoming frame bytes are appended to a fixed-size stack buffer without verifying that the current write index remains within bounds. An attacker capable of sending crafted serial or TCP-framed input can cause the current write index to exceed the buffer size, resulting in a write past the end of the stack buffer. This condition leads to memory corruption and application crash. | |
| Title | RIOT OS <= 2026.01-devel-317 Stack-Based Buffer Overflow in ethos Serial Frame Parser | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-05-14T02:09:06.739Z
Reserved: 2026-01-06T16:47:17.187Z
Link: CVE-2026-22214
Updated: 2026-01-13T18:50:37.755Z
Status : Analyzed
Published: 2026-01-12T23:15:52.453
Modified: 2026-01-21T17:43:51.967
Link: CVE-2026-22214
No data.
OpenCVE Enrichment
Updated: 2026-04-18T20:00:09Z