Executive brief
FreeRTOS-Plus-TCP is a networking library used by embedded devices to communicate over the internet and local networks. Vulnerabilities in how the library handles network configuration messages could allow a malicious device on the same local network to crash a device or potentially gain unauthorized access. This could lead to service disruptions or the compromise of sensitive data handled by the embedded system.
Technical details
The FreeRTOS-Plus-TCP stack is vulnerable to out-of-bounds read (CVE-2026-7425) and out-of-bounds write (CVE-2026-7426) conditions within the IPv6 Router Advertisement (RA) option parser. The root cause is insufficient validation of length fields in incoming RA packets, which allows memory operations to occur outside of intended buffer boundaries. An attacker on the same local network segment can exploit these flaws by sending specially crafted RA packets. No authentication or user interaction is required for exploitation. The issues have been addressed in versions V4.4.1 and V4.2.6.
Affected products
- Amazon Web Services FreeRTOS-Plus-TCP >=V4.0.0, <=V4.2.5; >=V4.3.0, <=V4.4.0
CVE identifiers
- CVE-2026-7426
- CVE-2026-7425
Timeline
- 2026-04-29: disclosed
- 2026-04-29: patched: Fixed in versions V4.4.1 and V4.2.6