CVE-2025-11618

Severity CVSS v4.0:
MEDIUM
Type:
CWE-476 NULL Pointer Dereference
Publication date:
10/10/2025
Last modified:
31/10/2025

Description

A missing validation check in FreeRTOS-Plus-TCP&amp;#39;s UDP/IPv6 packet processing code can lead to an invalid pointer dereference when receiving a UDP/IPv6 packet with an incorrect IP version field in the packet header. This issue only affects applications using IPv6.<br /> <br /> We recommend upgrading to the latest version and ensure any forked or derivative code is patched to incorporate the new fixes.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:amazon:freertos-plus-tcp:*:*:*:*:*:*:*:* 4.0.0 (including) 4.3.4 (excluding)