V4.2.3
Changes between FreeRTOS-Plus-TCP V4.2.3 and V4.2.2 released June 04, 2025:
- It was possible to cause an out-of-bounds write when processing LLMNR
or mDNS queries with very long DNS names. This issue only affects systems
using Buffer Allocation Scheme 1 with LLMNR or mDNS enabled.
This issue has been fixed by adding checks to prevent out of bounds write.
We would like to thank Paschal Amusuo (@AmPaschal),
James C Davis (@davisjam), Taylor Le Lievre (@tlelievre26), and
Aravind Kumar Machiry (@Machiry) of Purdue University for collaborating
on this issue through the coordinated vulnerability disclosure process. - Replace any missing functions by assert-false in all CBMC proofs to
improve tests. We would like to thank @tautschnig for their contribution. - Adjust CBMC proof tooling to support CBMC v6.
We would like to thank @tautschnig for their contribution.
SHA256 of FreeRTOS-Plus-TCP-V4.2.3.zip: 8bf6baeef04b68f169066094560b7ea2c4b8a4fa85b40902c2755f2a10d8606d