Where
-Infinity
0

Vendor Risk Score

See how freertos compares to other vendors in security performance

View Risk Score →
Severity
8.2
AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with configUSEQUEUESETS=1 to read privileged kernel memory. To remediate this issue, users should upgrade to version 11.3.1 or later.

First published (updated )
Severity
8.3
AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H

Missing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 might allow local users to corrupt secure-world heap metadata via an out-of-bounds write with an undersized stack size parameter. To remediate this issue, users should upgrade to version 11.3.1 or later.

First published (updated )
Severity
8.3
Use After Free
AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:H

Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users to cause a use-after-free condition in secure-world memory via the SVC handler for secure context deallocation. To remediate this issue, users should upgrade to version 11.3.1 or later.

First published (updated )
Severity
8.7
EPSS
0.39%
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet.

To remediate this issue, users should upgrade to v5.0.1.

First published (updated )
Severity
6.1
EPSS
0.02%
Buffer Overflow
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause memory corruption by sending a crafted Router Advertisement with a prefix length value exceeding the maximum valid length, resulting in a heap buffer overflow. Users processing IPv4 RA only are not impacted.

To mitigate this issue, users should upgrade to the fixed version when available.

First published (updated )
Severity
6
EPSS
0.02%
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause a denial of service (device crash) by sending a crafted Router Advertisement with a truncated PREFIXINFORMATION option that is smaller than the expected structure size.

To mitigate this issue, users should upgrade to the fixed version when available.

First published (updated )
Severity
7.2
EPSS
0.02%
Integer Underflow
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Integer underflow in the DHCPv6 sub-option parser in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network actor to corrupt the device's IPv6 address assignment, DNS configuration, and lease times, and to cause a denial of service (permanent IP task freeze requiring hardware reset) by sending a single crafted DHCPv6 packet.

The issue is present whenever DHCPv6 is enabled.

To mitigate this issue, users should upgrade to version V4.2.6 or V4.4.1 or newer.

First published (updated )
Severity
6
EPSS
0.02%
Integer Underflow
AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Integer underflow in the ICMP and ICMPv6 echo reply handlers in FreeRTOS-Plus-TCP before V4.4.1 and V4.2.6 allows an adjacent network user to cause a denial of service (device crash) when outgoing ping support is enabled, because header sizes are subtracted from a packet length field without validating the field is large enough, resulting in a heap out-of-bounds read of up to approximately 65KB.

To mitigate this issue, users should upgrade to the fixed version when available.

First published (updated )
Severity
7.1
EPSS
0.03%
Input Validation
AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Insufficient packet validation in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to bypass all checksum and minimum-size validation by spoofing the Ethernet source MAC address to match one of the device's own registered endpoints, because the loopback detection mechanism skips all input validation for packets whose source MAC matches a local endpoint.

To mitigate this issue, users should upgrade to the fixed version when available.

First published (updated )
Severity
5.3
Null Pointer Dereference
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

A missing validation check in FreeRTOS-Plus-TCP's UDP/IPv6 packet processing code can lead to an invalid pointer dereference when receiving a UDP/IPv6 packet with an incorrect IP version field in the packet header. This issue only affects applications using IPv6.

We recommend upgrading to the latest version and ensure any forked or derivative code is patched to incorporate the new fixes.

First published (updated )
Severity
5.4
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

A missing validation check in FreeRTOS-Plus-TCP's IPv6 packet processing code can lead to an out-of-bounds read when receiving a IPv6 packet with incorrect payload lengths in the packet header. This issue only affects applications using IPv6.

We recommend users upgrade to the latest version and ensure any forked or derivative code is patched to incorporate the new fixes.

First published (updated )
Severity
5.4
AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

A missing validation check in FreeRTOS-Plus-TCP's ICMPv6 packet processing code can lead to an out-of-bounds read when receiving ICMPv6 packets of certain message types which are smaller than the expected size. These issues only affect applications using IPv6.

Users should upgrade to the latest version and ensure any forked or derivative code is patched to incorporate the new fixes.

First published (updated )
Severity
7.5
EPSS
0.02%
Buffer Overflow
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

We have identified a buffer overflow issue allowing out-of-bounds write when processing LLMNR or mDNS queries with very long DNS names. This issue only affects systems using Buffer Allocation Scheme 1 with LLMNR or mDNS enabled.

Users should upgrade to the latest version and ensure any forked or derivative code is patched to incorporate the new fixes.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203