CVE-2026-7422 Details
Description
Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the device's own registered endpoints, because the loopback detection mechanism skips all input validation for packets whose source MAC matches a local endpoint. To mitigate this issue, users should upgrade to the fixed version when available.
A vulnerability in FreeRTOS-Plus-TCP versions 4.0.0 through 4.2.5 and 4.3.0 through 4.4.0 allows an adjacent network device to bypass checksum and minimum-size validation in IPv4 and IPv6 packet processing. This is achieved by spoofing the Ethernet source MAC address to match one of the device's registered endpoints. The TCP stack's loopback detection mechanism then skips the usual input validation, potentially leading to improper packet handling.
Users are advised to upgrade to FreeRTOS-Plus-TCP versions 4.2.6 or 4.4.1, and to patch any forked or derivative code to incorporate these fixes.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-021-aws/ | AMZN | Vendor Advisory |
| https://github.com/FreeRTOS/FreeRTOS-Plus-TCP/releases/tag/V4.2.6 | AMZN | Release Notes |
| https://github.com/FreeRTOS/FreeRTOS-Plus-TCP/releases/tag/V4.4.1 | AMZN | Release Notes |
| https://github.com/FreeRTOS/FreeRTOS-Plus-TCP/security/advisories/GHSA-jpw4-6h59-62w9 | AMZN | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-290 | Authentication Bypass by Spoofing | AMZN |
Affected Products
| Product | Versions |
|---|---|
| amazon freertos-plus-tcp | >= 4.0.0, < 4.2.6 >= 4.3.0, < 4.4.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 4, 2026 | Initial Analysis | [email protected] |
| Apr 29, 2026 | New CVE Received | AMZN |