CVE-2026-7426

Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause memory corruption by sending a crafted Router Advertisement with a prefix length value exceeding the maximum valid length, resulting in a heap buffer overflow. Users processing IPv4 RA only are not impacted. To mitigate this issue, users should upgrade to the fixed version when available.
Configurations

No configuration.

History

30 Apr 2026, 15:13

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-29 20:16

Updated : 2026-04-30 15:13


NVD link : CVE-2026-7426

Mitre link : CVE-2026-7426

CVE.ORG link : CVE-2026-7426


JSON object : View

Products Affected

No product.

CWE
CWE-787

Out-of-bounds Write