2026-023-AWS

Issue with FreeRTOS-Plus-TCP - IPv6 Router Advertisement Memory Safety Issues

Published
April 29, 2026
Last Modified

🔗 CVE IDs covered (2)

📋 Description

Bulletin ID: 2026-023-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/29 12:30 PM PDT Description: FreeRTOS-Plus-TCP is an open source TCP/IP stack implementation designed for FreeRTOS, providing a standard Berkeley sockets interface and support for essential networking protocols including IPv6, ARP, DHCP, DNS, and Router Advertisement (RA). We identified CVE-2026-7425 and CVE-2026-7426, one of them being out-of-bounds read and another one being out-of-bounds write issues respectively in the IPv6 Router Advertisement option parser where insufficient validation of length fields allows memory operations without proper bounds checking. Either issue can be exploited by any device on the local network that can send crafted Router Advertisement packets. No authentication or user interaction is required. Impacted versions: >=V4.0.0 AND =V4.3.0 AND
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

🔗 References (1)