CVE-2019-1000006: Riot-OS Riot
Critical severity, CVSS 9.8. EPSS: 1.6% chance of exploitation in the next 30 days.
RIOT RIOT-OS version after commit 7af03ab624db0412c727eed9ab7630a5282e2fd3 contains a Buffer Overflow vulnerability in sock_dns, an implementation of the DNS protocol utilizing the RIOT sock API that can result in Remote code executing. This attack appears to be exploitable via network connectivity.
Affected products
- Riot-OS Riot: from 2017.04, before 2018.10.1 (fixed in 2018.10.1)
Published 2019-02-04. Last modified 2026-06-17.