CVE-2025-5688: Amazon Freertos

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

We have identified a buffer overflow issue allowing out-of-bounds write when processing LLMNR or mDNS queries with very long DNS names. This issue only affects systems using Buffer Allocation Scheme 1 with LLMNR or mDNS enabled. Users should upgrade to the latest version and ensure any forked or derivative code is patched to incorporate the new fixes.

Affected products

  • Amazon Freertos: from 2.3.4, before 4.3.2 (fixed in 4.3.2)

Published 2025-06-04. Last modified 2026-06-17.