Junglewise Threat Intelligence

CVE-2026-7422: Amazon FreeRTOS-Plus-TCP multiple vulnerabilities in ICMP and packet validation

CVE-2026-7422 · Severity: high · Published 2026-04-29

Technologies: Amazon Web Services FreeRTOS-Plus-TCP, Amazon AWS. Vendors: Amazon Web Services, Amazon.

Executive brief

FreeRTOS-Plus-TCP is a networking library used by embedded devices to communicate over the internet or local networks. Two vulnerabilities have been identified that allow nearby attackers on the same network to bypass security checks or crash the device. An exploit could lead to a complete service outage for the affected hardware, potentially disrupting industrial or IoT operations.

Technical details

Two vulnerabilities exist in the FreeRTOS-Plus-TCP stack. CVE-2026-7422 involves insufficient packet validation in IPv4/IPv6 receive paths; an adjacent attacker can bypass checksum and minimum-size validations by spoofing the Ethernet source MAC address to match the target's own endpoint. CVE-2026-7423 is an integer underflow in the ICMP/ICMPv6 echo reply handlers occurring when outgoing ping support is enabled. This underflow happens when header sizes are subtracted from a packet length field without bounds checking, resulting in a heap out-of-bounds read and a device crash. These issues are fixed in versions V4.4.1 and V4.2.6.

Affected products

  • Amazon Web Services FreeRTOS-Plus-TCP >=V4.0.0, <=V4.2.5; >=V4.3.0, <=V4.4.0

CVE identifiers

  • CVE-2026-7422
  • CVE-2026-7423

Timeline

  • 2026-04-29: disclosed
  • 2026-04-29: advisory

References

Related threats