---
id: CVE-2025-11616
title: "A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of certain message types which are smaller than the expected size.\_These issues only affect a…"
summary: "A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of certain message types which are smaller than the expected size.\_These issues only affect a…"
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L'
cwe:
  - CWE-126
vendor: amazon
product: freertos-plus-tcp
affected:
  - 'freertos-plus-tcp >= 4.0.0, < 4.3.4'
patched:
  - freertos-plus-tcp 4.3.4
published: '2025-10-10'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11616'
references:
  - url: 'https://aws.amazon.com/security/security-bulletins/AWS-2025-023/'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: 'https://github.com/FreeRTOS/FreeRTOS-Plus-TCP/releases/tag/V4.3.4'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: >-
      https://github.com/FreeRTOS/FreeRTOS-Plus-TCP/security/advisories/GHSA-8j9h-xjm9-8j6j
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
tags:
  - nvd
epss: 0.00306
epssPercentile: 0.2137
ingestedAt: '2026-10-08T13:42:55.085Z'
---

## Overview

A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of certain message types which are smaller than the expected size. These issues only affect applications using IPv6.

Users should upgrade to the latest version and ensure any forked or derivative code is patched to incorporate the new fixes.

## Affected

- `freertos-plus-tcp >= 4.0.0, < 4.3.4`

## Remediation

Upgrade past the affected range:

- `freertos-plus-tcp 4.3.4`
