CVE-2026-7425: Out-of-Bounds Read in Router Advertisement Option Parser in FreeRTOS-Plus-TCP
Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause a denial of service (device crash) by sending a crafted Router Advertisement with a truncated PREFIX_INFORMATION option that is smaller than the expected structure size. To mitigate this issue, users should upgrade to the fixed version when available.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7425?
CVE-2026-7425 is classified as a denial of service vulnerability due to out-of-bounds read issues that can lead to device crashes.
How do I fix CVE-2026-7425?
To fix CVE-2026-7425, upgrade FreeRTOS-Plus-TCP to version 4.4.1 or later, or 4.2.6 or later.
What components are affected by CVE-2026-7425?
CVE-2026-7425 affects FreeRTOS-Plus-TCP versions prior to 4.2.6 and 4.4.1 due to insufficient option length validation.
Who can exploit CVE-2026-7425?
An adjacent network actor can exploit CVE-2026-7425 by sending crafted Router Advertisement packets.
What are the potential impacts of exploiting CVE-2026-7425?
Exploiting CVE-2026-7425 can cause a denial of service, resulting in device crashes or unresponsiveness.