CVE-2026-7426 Details
Description
Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause memory corruption by sending a crafted Router Advertisement with a prefix length value exceeding the maximum valid length, resulting in a heap buffer overflow. Users processing IPv4 RA only are not impacted. To mitigate this issue, users should upgrade to the fixed version when available.
A heap buffer overflow vulnerability has been identified in FreeRTOS-Plus-TCP versions 4.0.0 through 4.2.5 and 4.3.0 through 4.4.0. The issue arises from insufficient validation of the prefix length field in IPv6 Router Advertisement processing. An adjacent network actor can exploit this vulnerability by sending a crafted Router Advertisement with an excessively large prefix length, leading to memory corruption. This vulnerability does not affect users who only process IPv4 Router Advertisements.
Users are advised to upgrade to FreeRTOS-Plus-TCP versions 4.2.6 or 4.4.1. If an immediate upgrade is not possible, consider implementing network-level filtering to block untrusted Router Advertisement packets or deploying devices on isolated network segments where rogue Router Advertisement packets cannot be injected.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://aws.amazon.com/security/security-bulletins/2026-023-aws/ | AMZN | Vendor Advisory |
| https://github.com/FreeRTOS/FreeRTOS-Plus-TCP/releases/tag/V4.2.6 | AMZN | Release Notes |
| https://github.com/FreeRTOS/FreeRTOS-Plus-TCP/releases/tag/V4.4.1 | AMZN | Release Notes |
| https://github.com/FreeRTOS/FreeRTOS-Plus-TCP/security/advisories/GHSA-97qg-4359-xm3x | AMZN | PatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | AMZN |
Affected Products
| Product | Versions |
|---|---|
| amazon freertos-plus-tcp | >= 4.0.0, < 4.2.6 >= 4.3.0, < 4.4.1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | AMZN |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 4, 2026 | Initial Analysis | [email protected] |
| Apr 29, 2026 | CVE Modified | AMZN |
| Apr 29, 2026 | New CVE Received | AMZN |