Issue with FreeRTOS-Plus-TCP - IPv6 Router Advertisement Memory Safety Issues
UnratedCVE-2026-7425 · Published Apr 29, 2026 · updated Sep 25, 2026
Bulletin ID: 2026-023-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 04/29/2026 11:45 AM PDT Description: FreeRTOS-Plus-TCP is an open source TCP/IP stack implementation designed for FreeRTOS, providing a standard Berkeley sockets interface and support for essential networking protocols including IPv6, ARP, DHCP, DNS, and Router Advertisement (RA). We identified CVE-2026-7425 and CVE-2026-7426 , one of them being out-of-bounds read and another one being out-of-bounds write issues respectively in the IPv6 Router Advertisement option parser where insufficient validation of length fields allows memory operations without proper bounds checking. Either issue can be exploited by any device on the local network that can send crafted Router Advertisement packets. No authentication or user interaction is required. Impacted versions: >=V4.0.0 AND =V4.3.0 AND Resolution: This issue has been addressed in FreeRTOS-Plus-TCP version V4.4.1 and V4.2.6 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: If upgrading is not immediately possible, consider the fol...
Affected versions
Details and references
Bulletin ID: 2026-023-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 04/29/2026 11:45 AM PDT Description: FreeRTOS-Plus-TCP is an open source TCP/IP stack implementation designed for FreeRTOS, providing a standard Berkeley sockets interface and support for essential networking protocols including IPv6, ARP, DHCP, DNS, and Router Advertisement (RA). We identified CVE-2026-7425 and CVE-2026-7426 , one of them being out-of-bounds read and another one being out-of-bounds write issues respectively in the IPv6 Router Advertisement option parser where insufficient validation of length fields allows memory operations without proper bounds checking. Either issue can be exploited by any device on the local network that can send crafted Router Advertisement packets. No authentication or user interaction is required. Impacted versions: >=V4.0.0 AND =V4.3.0 AND Resolution: This issue has been addressed in FreeRTOS-Plus-TCP version V4.4.1 and V4.2.6 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: If upgrading is not immediately possible, consider the following mitigations: Implement network-level filtering to block untrusted Router Advertisement packets on the local network segment Deploy devices on isolated network segments where rogue RA packets cannot be injected References: CVE-2026-7425 CVE-2026-7426 GHSA-gffr-xgjg-jh9j GHSA-97qg-4359-xm3x Acknowledgment: We would like to thank Espilon for collaborating on this issue through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-023-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} Issue with FreeRTOS-Plus-TCP - IPv6 Router Advertisement Memory Safety Issues Bulletin ID: 2026-023-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 04/29/2026 11:45 AM PDT Description: FreeRTOS-Plus-TCP is an open source TCP/IP stack implementation designed for FreeRTOS, providing a standard Berkeley sockets interface and support for essential networking protocols including IPv6, ARP, DHCP, DNS, and Router Advertisement (RA). We identified CVE-2026-7425 and CVE-2026-7426 , one of them being out-of-bounds read and another one being out-of-bounds write issues respectively in the IPv6 Router Advertisement option parser where insufficient validation of length fields allows memory operations without proper bounds checking. Either issue can be exploited by any device on the local network that can send crafted Router Advertisement packets. No authentication or user interaction is required. Impacted versions: >=V4.0.0 AND =V4.3.0 AND Resolution: This issue has been addressed in FreeRTOS-Plus-TCP version V4.4.1 and V4.2.6 . We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes. Workarounds: If upgrading is not immediately possible, consider the following mitigations: Implement network-level filtering to block untrusted Router Advertisement packet
- Severity from
- no source yet
- Also known as
- CVE-2026-7426
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 30 | OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials | High7.2 | 1.103.0 |
| Apr 30 | OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials | Unrated | No fix yet |
| Apr 29 | Issue with FreeRTOS-Plus-TCP - MAC Address Validation Bypass and ICMP Echo Reply Integer... | Unrated | No fix yet |
| Apr 29 | Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP | Unrated | No fix yet |
| Apr 27 | Arbitrary Code Execution via Sandbox Bypass in QnABot on AWS | Unrated | No fix yet |
| Apr 24 | Issue with AWS Ops Wheel (CVE-2026-6911 and CVE-2026-6912 | Unrated | No fix yet |