CVE-2026-7424: Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP
Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (permanent IP task freeze requiring hardware reset) by sending a single crafted DHCPv6 packet. The issue is present whenever DHCPv6 is enabled. To mitigate this issue, users should upgrade to version V4.2.6 or V4.4.1 or newer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7424?
CVE-2026-7424 is considered a high severity vulnerability due to the potential for device corruption and denial of service.
How do I fix CVE-2026-7424?
To fix CVE-2026-7424, upgrade FreeRTOS-Plus-TCP to version 4.4.1 or later, or to version 4.2.6.
What systems are affected by CVE-2026-7424?
CVE-2026-7424 affects FreeRTOS-Plus-TCP versions prior to 4.4.1 and 4.2.6.
What types of attacks can CVE-2026-7424 facilitate?
CVE-2026-7424 may allow an adjacent network actor to corrupt IPv6 address assignments and DNS configurations.
Is CVE-2026-7424 a remote exploit?
Yes, CVE-2026-7424 can be exploited remotely by an adjacent network actor.