CVE-2026-29013

Name
CVE-2026-29013
Description
libcoap contains out-of-bounds read vulnerabilities in OSCORE Appendix B.2 CBOR unwrap handling where get_byte_inc() in src/oscore/oscore_cbor.c relies solely on assert() for bounds checking, which is removed in release builds compiled with NDEBUG. Attackers can send crafted CoAP requests with malformed OSCORE options or responses during OSCORE negotiation to trigger out-of-bounds reads during CBOR parsing and potentially cause out-of-bounds reads through integer wraparound in allocation size computation.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
disclosure@vulncheck.com https://github.com/obgm/libcoap/commit/b7847c4dbb0dbee7c90b09a673d4cae256f03718
disclosure@vulncheck.com https://www.vulncheck.com/advisories/libcoap-out-of-bounds-read-in-oscore-cbor-unwrap-handling

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:libcoap:libcoap:*:*:*:*:*:*:*:* libcoap >= None < 4.3.5b

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libcoap edge-community 4.3.5a-r0 Sören Tempel <soeren+alpine@soeren-tempel.net> possibly vulnerable
libcoap edge-community 4.3.5-r0 Sören Tempel <soeren+alpine@soeren-tempel.net> possibly vulnerable
libcoap 3.23-community 4.3.5-r0 Sören Tempel <soeren+alpine@soeren-tempel.net> possibly vulnerable