---
id: CVE-2025-11617
title: "A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with incorrect payload lengths in the packet header.\_This issue only affects applications using …"
summary: "A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with incorrect payload lengths in the packet header.\_This issue only affects applications using …"
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L'
cwe:
  - CWE-126
vendor: amazon
product: freertos-plus-tcp
affected:
  - 'freertos-plus-tcp >= 4.0.0, < 4.3.4'
patched:
  - freertos-plus-tcp 4.3.4
published: '2025-10-10'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11617'
references:
  - url: 'https://aws.amazon.com/security/security-bulletins/AWS-2025-023/'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: 'https://github.com/FreeRTOS/FreeRTOS-Plus-TCP/releases/tag/V4.3.4'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: >-
      https://github.com/FreeRTOS/FreeRTOS-Plus-TCP/security/advisories/GHSA-wmjr-wm93-cvv2
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
tags:
  - nvd
epss: 0.00306
epssPercentile: 0.21371
ingestedAt: '2026-10-08T13:42:55.085Z'
---

## Overview

A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with incorrect payload lengths in the packet header. This issue only affects applications using IPv6.

We recommend users upgrade to the latest version and ensure any forked or derivative code is patched to incorporate the new fixes.

## Affected

- `freertos-plus-tcp >= 4.0.0, < 4.3.4`

## Remediation

Upgrade past the affected range:

- `freertos-plus-tcp 4.3.4`
