bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud

tag: FreeRTOS-Plus-TCP

show all
Thursday, August 20, 2026

FreeRTOS-Plus-TCP DHCPv6 Parser Vulnerability Requires Immediate Patching

FreeRTOS-Plus-TCP versions 4.0.0–4.2.5 and 4.3.0–4.4.0 are vulnerable to CVE-2026-7424, an integer underflow in the DHCPv6 sub-option parser. An adjacent network attacker can corrupt IPv6 configuration, DNS settings, and DHCP leases, potentially freezing the IP task and requiring a hardware reset. Action required: upgrade to a patched version immediately if you're running affected releases.

source: [aws/security-bulletin]

FreeRTOS-Plus-TCP: Two Critical Vulnerabilities Require Immediate Patching

FreeRTOS-Plus-TCP versions 4.0.0–4.2.5 and 4.3.0–4.4.0 have two nasty security flaws. CVE-2026-7422 lets adjacent network devices bypass MAC address validation and checksum checks, while CVE-2026-7423 causes integer underflow in ICMP handlers, potentially crashing your device. If you're running affected versions with outgoing ping enabled, you need to update ASAP.

source: [aws/security-bulletin]