PT-2026-48351 · Espressif Systems · Esp-Idf
CVE-2026-45329
·
Published
2026-06-10
·
Updated
2026-06-11
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ESF-IDF versions 5.5.4
ESF-IDF version 6.0
Description
Several ESP-TEE secure-service wrappers in
esp secure services.c and esp secure services iram.c fail to validate all caller-supplied pointer arguments. Since the TEE-protected hardware peripherals, such as ECC, SHA, and SPI, operate in RISC-V machine mode (M-mode) with full address-space access, a caller can provide pointers to TEE-exclusive memory. This allows the peripheral to read TEE memory and return derived results to the REE (Rich Execution Environment). Depending on the wrapper, the output may consist of raw bytes from TEE memory, a computed function of TEE memory recoverable via repeated calls, or a single bit per call acting as an oracle for the incremental disclosure of sensitive TEE-resident data.Recommendations
Update version 5.5.4 to 5.5.5
Update version 6.0 to 6.0.1
Exploit
Fix
Information Disclosure
Out of bounds Read
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Esp-Idf