Junglewise Threat Intelligence

CVE-2025-11617: FreeRTOS-Plus-TCP multiple memory safety vulnerabilities in IPv6 stack

CVE-2025-11617 · Severity: high · Published 2025-10-10

Technologies: Amazon Web Services FreeRTOS-Plus-TCP, Amazon AWS. Vendors: Amazon Web Services, Amazon.

Executive brief

FreeRTOS-Plus-TCP is a networking library used by embedded devices to communicate over the internet. Multiple vulnerabilities have been identified that could allow an attacker to crash these devices or potentially access sensitive information by sending specially crafted network packets. This affects any device using this library with IPv6 enabled, potentially leading to service disruptions in industrial, medical, or consumer IoT environments.

Technical details

FreeRTOS-Plus-TCP versions v4.0.0 through v4.3.3 are vulnerable to three distinct memory safety issues when IPv6 is enabled. CVE-2025-11616 and CVE-2025-11617 involve buffer over-reads triggered by ICMPv6 packets smaller than expected or IPv6 packets with incorrect payload length headers. CVE-2025-11618 involves an invalid pointer dereference when processing UDP/IPv6 packets with an incorrect IP version field. These vulnerabilities can be exploited by a remote attacker sending malformed packets over the network without authentication. Successful exploitation can result in a denial of service (system crash) or potential information leakage from the stack. The issues are resolved in version 4.3.4.

Affected products

  • Amazon Web Services FreeRTOS-Plus-TCP v4.0.0 to v4.3.3

CVE identifiers

  • CVE-2025-11617
  • CVE-2025-11618
  • CVE-2025-11616

Timeline

  • 2025-10-10: advisory: AWS published security bulletin AWS-2025-023
  • 2025-10-10: patched: Fixed in FreeRTOS-Plus-TCP version 4.3.4

References

Related threats