Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP
UnratedCVE-2026-7424 · Published Apr 29, 2026 · updated Sep 25, 2026
Bulletin ID: 2026-022-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 04/29/2026 11:45 AM PDT Description: FreeRTOS-Plus-TCP is an open-source, scalable TCP/IP stack for FreeRTOS. We identified CVE-2026-7424 , where an integer underflow issue in the DHCPv6 sub-option parser could allow an adjacent network user to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (IP task freeze requiring hardware reset). Impacted versions: FreeRTOS-Plus-TCP >=V4.0.0 AND =V4.3.0 AND Resolution: This issue has been addressed in FreeRTOS-Plus-TCP version V4.4.1 and V4.2.6 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Users who cannot immediately upgrade can disable DHCPv6 by setting ipconfigUSE_DHCPv6 to 0 in their FreeRTOSIPConfig.h configuration file. Note that this workaround requires manual IPv6 address configuration. References: CVE-2026-7424 GHSA-wrhm-c99p-2p8g Acknowledgment: We would like to thank security researcher @Eun0us | Espilon for collaborating on this issue through the coor...
Affected versions
Details and references
Bulletin ID: 2026-022-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 04/29/2026 11:45 AM PDT Description: FreeRTOS-Plus-TCP is an open-source, scalable TCP/IP stack for FreeRTOS. We identified CVE-2026-7424 , where an integer underflow issue in the DHCPv6 sub-option parser could allow an adjacent network user to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (IP task freeze requiring hardware reset). Impacted versions: FreeRTOS-Plus-TCP >=V4.0.0 AND =V4.3.0 AND Resolution: This issue has been addressed in FreeRTOS-Plus-TCP version V4.4.1 and V4.2.6 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Users who cannot immediately upgrade can disable DHCPv6 by setting ipconfigUSE_DHCPv6 to 0 in their FreeRTOSIPConfig.h configuration file. Note that this workaround requires manual IPv6 address configuration. References: CVE-2026-7424 GHSA-wrhm-c99p-2p8g Acknowledgment: We would like to thank security researcher @Eun0us | Espilon for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-022-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-7424 - Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP Bulletin ID: 2026-022-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 04/29/2026 11:45 AM PDT Description: FreeRTOS-Plus-TCP is an open-source, scalable TCP/IP stack for FreeRTOS. We identified CVE-2026-7424 , where an integer underflow issue in the DHCPv6 sub-option parser could allow an adjacent network user to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (IP task freeze requiring hardware reset). Impacted versions: FreeRTOS-Plus-TCP >=V4.0.0 AND =V4.3.0 AND Resolution: This issue has been addressed in FreeRTOS-Plus-TCP version V4.4.1 and V4.2.6 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: Users who cannot immediately upgrade can disable DHCPv6 by setting ipconfigUSE_DHCPv6 to 0 in their FreeRTOSIPConfig.h configuration file. Note that this workaround requires manual IPv6 address configuration. References: CVE-2026-7424 GHSA-wrhm-c99p-2p8g Acknowledgment: We would like to thank security researcher @Eun0us | Espilon for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns. {"data":{"items":[{"fields":{"footer":"{ "createAccountButtonLabel": "Create an AWS account", "createAccountButtonURL": "https://signin.aws.amazon.com/signup?request_type=register", "backToTopText": "Back to top", "eoeText": "Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability or other legall
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 30 | OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials | High7.2 | 1.103.0 |
| Apr 30 | OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials | Unrated | No fix yet |
| Apr 29 | Issue with FreeRTOS-Plus-TCP - MAC Address Validation Bypass and ICMP Echo Reply Integer... | Unrated | No fix yet |
| Apr 29 | Issue with FreeRTOS-Plus-TCP - IPv6 Router Advertisement Memory Safety Issues | Unrated | No fix yet |
| Apr 27 | Arbitrary Code Execution via Sandbox Bypass in QnABot on AWS | Unrated | No fix yet |
| Apr 24 | Issue with AWS Ops Wheel (CVE-2026-6911 and CVE-2026-6912 | Unrated | No fix yet |