CVE-2025-11616

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
10/10/2025
Last modified:
31/10/2025

Description

A missing validation check in FreeRTOS-Plus-TCP&amp;#39;s ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of certain message types which are smaller than the expected size. These issues only affect applications using IPv6.<br /> <br /> Users should upgrade to the latest version and ensure any forked or derivative code is patched to incorporate the new fixes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:amazon:freertos-plus-tcp:*:*:*:*:*:*:*:* 4.0.0 (including) 4.3.4 (excluding)