A vulnerability, which was classified as very critical, has been found in Contiki-NG. This impacts the function lwm2m_tlv_read of the file os/services/lwm2m/lwm2m-tlv.c of the component LwM2M TLV parser. Performing a manipulation of the argument length results in out-of-bounds read.

This vulnerability is known as CVE-2026-5855. Remote exploitation of the attack is possible. No exploit is available.

To fix this issue, it is recommended to deploy a patch.