{"id":"CVE-2025-5688","summary":"Out of Bounds Write in FreeRTOS-Plus-TCP","details":"We have identified a buffer overflow issue allowing out-of-bounds write when processing LLMNR or mDNS queries with very long DNS names. This issue only affects systems using Buffer Allocation Scheme 1 with LLMNR or mDNS enabled.\n\n\nUsers should upgrade to the latest version and ensure any forked or derivative code is patched to incorporate the new fixes.","aliases":["GHSA-5x4f-fvv8-wr65"],"modified":"2026-08-12T03:51:36.577009903Z","published":"2025-06-04T17:09:54.718Z","database_specific":{"cwe_ids":["CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/5xxx/CVE-2025-5688.json","cna_assigner":"AMZN"},"references":[{"type":"ADVISORY","url":"https://aws.amazon.com/security/security-bulletins/AWS-2025-012/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/5xxx/CVE-2025-5688.json"},{"type":"ADVISORY","url":"https://github.com/FreeRTOS/FreeRTOS-Plus-TCP/security/advisories/GHSA-5x4f-fvv8-wr65"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-5688"},{"type":"FIX","url":"https://github.com/FreeRTOS/FreeRTOS-Plus-TCP/releases/tag/V4.3.2"},{"type":"PACKAGE","url":"https://github.com/FreeRTOS/FreeRTOS-Plus-TCP"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/freertos/freertos-plus-tcp","events":[{"introduced":"de36c605a89a40d81c385dfcd0e8f6bf4017eb0e"},{"fixed":"21c0438b73c7a22f8c7b08d0ff5ac8a5e1e21a97"}],"database_specific":{"extracted_events":[{"introduced":"2.3.4"},{"fixed":"4.3.2"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["V4.3.1","V4.0.0-appsec","V2.4.0","V2.3.4"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-5688.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}