Issue with FreeRTOS-Plus-TCP - MAC Address Validation Bypass and ICMP Echo Reply Integer...
UnratedCVE-2026-7422 · Published Apr 29, 2026 · updated Sep 25, 2026
Bulletin ID: 2026-021-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 04/29/2026 11:45 AM PDT Description: FreeRTOS-Plus-TCP is a scalable, open source, and thread-safe TCP/IP stack for FreeRTOS. CVE-2026-7422 : Insufficient packet validation in the IPv4 and IPv6 receive paths allows an adjacent network device to send a packet that bypasses checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the target device's own registered endpoints. CVE-2026-7423 : Integer underflow in the ICMP and ICMPv6 echo reply handlers allows an adjacent network device to cause a denial of service (device crash) when outgoing ping support is enabled, because header sizes are subtracted from a packet length field without validating the field is large enough, resulting in a heap out-of-bounds read. Impacted versions: >=V4.0.0 AND =V4.3.0 AND Resolution: This issue has been addressed in FreeRTOS-Plus-TCP version V4.4.1 and V4.2.6 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: CVE-2026-7422 (ICMP integer underflow) can be mitiga...
Affected versions
Details and references
Bulletin ID: 2026-021-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 04/29/2026 11:45 AM PDT Description: FreeRTOS-Plus-TCP is a scalable, open source, and thread-safe TCP/IP stack for FreeRTOS. CVE-2026-7422 : Insufficient packet validation in the IPv4 and IPv6 receive paths allows an adjacent network device to send a packet that bypasses checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the target device's own registered endpoints. CVE-2026-7423 : Integer underflow in the ICMP and ICMPv6 echo reply handlers allows an adjacent network device to cause a denial of service (device crash) when outgoing ping support is enabled, because header sizes are subtracted from a packet length field without validating the field is large enough, resulting in a heap out-of-bounds read. Impacted versions: >=V4.0.0 AND =V4.3.0 AND Resolution: This issue has been addressed in FreeRTOS-Plus-TCP version V4.4.1 and V4.2.6 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: CVE-2026-7422 (ICMP integer underflow) can be mitigated by disabling outgoing ping support by setting ipconfigSUPPORT_OUTGOING_PINGS to 0 in your FreeRTOSIPConfig.h configuration file, or by updating to a fixed version. Mitigating CVE-2026-7423 (MAC address validation bypass) requires updating to a fixed version. References: CVE-2026-7422 CVE-2026-7423 GHSA-jpw4-6h59-62w9 GHSA-7r59-2pgv-9v2r Acknowledgment: We would like to thank Espilon for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-021-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} Issue with FreeRTOS-Plus-TCP - MAC Address Validation Bypass and ICMP Echo Reply Integer Underflow Bulletin ID: 2026-021-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 04/29/2026 11:45 AM PDT Description: FreeRTOS-Plus-TCP is a scalable, open source, and thread-safe TCP/IP stack for FreeRTOS. CVE-2026-7422 : Insufficient packet validation in the IPv4 and IPv6 receive paths allows an adjacent network device to send a packet that bypasses checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the target device's own registered endpoints. CVE-2026-7423 : Integer underflow in the ICMP and ICMPv6 echo reply handlers allows an adjacent network device to cause a denial of service (device crash) when outgoing ping support is enabled, because header sizes are subtracted from a packet length field without validating the field is large enough, resulting in a heap out-of-bounds read. Impacted versions: >=V4.0.0 AND =V4.3.0 AND Resolution: This issue has been addressed in FreeRTOS-Plus-TCP version V4.4.1 and V4.2.6 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: CVE-2026-7422 (ICMP integer underflow) can be mitigated by disabling outgoing ping su
- Severity from
- no source yet
- Also known as
- CVE-2026-7423
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 30 | OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials | High7.2 | 1.103.0 |
| Apr 30 | OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials | Unrated | No fix yet |
| Apr 29 | Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP | Unrated | No fix yet |
| Apr 29 | Issue with FreeRTOS-Plus-TCP - IPv6 Router Advertisement Memory Safety Issues | Unrated | No fix yet |
| Apr 27 | Arbitrary Code Execution via Sandbox Bypass in QnABot on AWS | Unrated | No fix yet |
| Apr 24 | Issue with AWS Ops Wheel (CVE-2026-6911 and CVE-2026-6912 | Unrated | No fix yet |