Unknown · Freertos-Plus-Tcp · CVE-2026-7424
**Name of the Vulnerable Software and Affected Versions**
FreeRTOS-Plus-TCP versions prior to V4.2.6
FreeRTOS-Plus-TCP versions prior to V4.4.1
**Description**
An integer underflow in the DHCPv6 sub-option parser occurs whenever DHCPv6 is enabled. This allows an adjacent network actor to send a single crafted DHCPv6 packet to corrupt the device's IPv6 address assignment, DNS configuration, and lease times. This can lead to a denial of service, resulting in a permanent IP task freeze that requires a hardware reset.
**Recommendations**
Upgrade to version V4.2.6 or newer.
Upgrade to version V4.4.1 or newer.