CVE-2026-7425 Details
Description
Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause a denial of service (device crash) by sending a crafted Router Advertisement with a truncated PREFIX_INFORMATION option that is smaller than the expected structure size. To mitigate this issue, users should upgrade to the fixed version when available.
A denial-of-service vulnerability has been identified in FreeRTOS-Plus-TCP versions 4.0.0 through 4.2.5 and 4.3.0 through 4.4.0. The issue arises from insufficient validation of option lengths in the IPv6 Router Advertisement parser. This flaw allows an adjacent network actor to send a crafted Router Advertisement with a truncated PREFIX_INFORMATION option, causing a device crash.
Users are advised to upgrade to FreeRTOS-Plus-TCP versions 4.2.6 or 4.4.1. If an immediate upgrade is not possible, consider implementing network-level filtering to block untrusted Router Advertisement packets or deploying devices on isolated network segments where rogue Router Advertisement packets cannot be injected.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-023-aws/ | AMZN | Vendor Advisory |
| https://github.com/FreeRTOS/FreeRTOS-Plus-TCP/releases/tag/V4.2.6 | AMZN | Release Notes |
| https://github.com/FreeRTOS/FreeRTOS-Plus-TCP/releases/tag/V4.4.1 | AMZN | Release Notes |
| https://github.com/FreeRTOS/FreeRTOS-Plus-TCP/security/advisories/GHSA-gffr-xgjg-jh9j | AMZN | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | AMZN |
Affected Products
| Product | Versions |
|---|---|
| amazon freertos-plus-tcp | >= 4.0.0, < 4.2.6 >= 4.3.0, < 4.4.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 4, 2026 | Initial Analysis | [email protected] |
| Apr 29, 2026 | CVE Modified | AMZN |
| Apr 29, 2026 | New CVE Received | AMZN |