Buffer Over-read when receiving improperly sized ICMPv6 packets
Bulletin ID: AWS-2025-023 Scope: AWS Content Type: Important (requires attention) Publication Date: 2025/10/10 10:15 PM PDT We identified the following CVEs: CVE-2025-11616 - A Buffer Over-read when receiving ICMPv6 packets of certain message types which are smaller than the expected size. CVE-2025-11617 - A Buffer Over-read when receiving a IPv6 packet with incorrect payload lengths in the packet header. CVE-2025-11618 - An invalid pointer dereference when receiving a UDP/IPv6 packet with an incorrect IP version field in the packet header. Description: FreeRTOS-Plus-TCP is an open source TCP/IP stack implementation specifically designed for FreeRTOS. The stack provides a standard Berkeley sockets interface and supports essential networking protocols including IPv6, ARP, DHCP, DNS, LLMNR, mDNS, NBNS, RA, ND, ICMP, and ICMPv6. These issues only affect applications using IPv6. Affected versions: v4.0.0 to v4.3.3, if IPv6 support is enabled
CSIRTS triage
- What
- Buffer over-read issues when receiving improperly sized ICMPv6 packets.
- Who is affected
- Applications using IPv6 with FreeRTOS-Plus-TCP.
- Urgency
- Remediation is important to prevent potential crashes or unexpected behavior.
- Action
- Review and update the handling of ICMPv6 packets.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FreeRTOS-Plus-TCP
Get an email when a new FreeRTOS-Plus-TCP advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/aws-2025-023/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2025-116160.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-116170.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2025-116180.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2025-11616 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-11617 | coverage & exploitation status | NVD · CVE.org |
| CVE-2025-11618 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for Buffer Over-read when
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-68453: In the Linux kernel, the following vulnerability has been resolved: s390/zcrypt: Fix buffer ov…nvd · 2026-08-13
- mediumCVE-2026-18024: Buffer over-read in PostgreSQL ascii() SQL function allows a user to disclose up to 3 bytes af…nvd · 2026-08-13
- mediumCVE-2026-14678: Buffer over-read in PostgreSQL pg_trgm index picksplit function reads past end of a heap buffe…nvd · 2026-08-13
- mediumCVE-2026-68819: Buffer over-read in Windows Network File System allows an unauthorized attacker to deny servic…nvd · 2026-08-11
- mediumCVE-2026-65794: Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information…nvd · 2026-08-11
- highCVE-2026-64905: Buffer over-read in Microsoft Office Word allows an unauthorized attacker to execute code loca…nvd · 2026-08-11
More from AWS Security Bulletins
- unknownCVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool2026-08-25
- unknownCVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards2026-08-21
- unknownCVE-2026-77810 - Issue with Athena Federated Query Neptune Connector2026-08-21
- unknownIssue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-772372026-08-21
- unknownOngoing updates on Copy.fail and variants2026-08-20