Skip to content

V4.3.2

Compare
Choose a tag to compare
@tony-josi-aws tony-josi-aws released this 03 Jun 17:39
21c0438

Changes between FreeRTOS-Plus-TCP V4.3.2 and V4.3.1 released June 03, 2025:

It was possible to cause an out-of-bounds write when processing LLMNR or mDNS queries with very long DNS names. This issue only affects systems using Buffer Allocation Scheme 1 with LLMNR or mDNS enabled. This issue has been fixed by adding checks to prevent out of bounds write.

We would like to thank Paschal Amusuo (@AmPaschal), James C Davis (@davisjam), Taylor Le Lievre (@tlelievre26), and Aravind Kumar Machiry (@Machiry) of Purdue University for collaborating on this issue through the coordinated vulnerability disclosure process.