2026-022-AWS
CVE-2026-7424 - Integer Underflow in DHCPv6 Sub-Option Parser in FreeRTOS-Plus-TCP
🔗 CVE IDs covered (1)
📋 Description
Bulletin ID: 2026-022-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 2026/04/29 12:20 PM PDT
Description:
FreeRTOS-Plus-TCP is an open-source, scalable TCP/IP stack for FreeRTOS. We identified CVE-2026-7424, where an integer underflow issue in the DHCPv6 sub-option parser could allow an adjacent network user to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (IP task freeze requiring hardware reset).
Impacted versions: FreeRTOS-Plus-TCP >=V4.0.0 AND =V4.3.0 AND
Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.