Beveiligingsadvies

CVE-2026-7425

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-04-29 18:52:36
Laatst bijgewerkt 2026-04-29 22:14:08
Toegewezen door AMZN
CVSS-score 6.5
Status PUBLISHED

Beschrijving

Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause a denial of service (device crash) by sending a crafted Router Advertisement with a truncated PREFIX_INFORMATION option that is smaller than the expected structure size. To mitigate this issue, users should upgrade to the fixed version when available.