PT-2026-48351 · Espressif Systems · Esp-Idf

CVE-2026-45329

·

Published

2026-06-10

·

Updated

2026-06-11

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ESF-IDF versions 5.5.4 ESF-IDF version 6.0
Description Several ESP-TEE secure-service wrappers in esp secure services.c and esp secure services iram.c fail to validate all caller-supplied pointer arguments. Since the TEE-protected hardware peripherals, such as ECC, SHA, and SPI, operate in RISC-V machine mode (M-mode) with full address-space access, a caller can provide pointers to TEE-exclusive memory. This allows the peripheral to read TEE memory and return derived results to the REE (Rich Execution Environment). Depending on the wrapper, the output may consist of raw bytes from TEE memory, a computed function of TEE memory recoverable via repeated calls, or a single bit per call acting as an oracle for the incremental disclosure of sensitive TEE-resident data.
Recommendations Update version 5.5.4 to 5.5.5 Update version 6.0 to 6.0.1

Exploit

Fix

Information Disclosure

Out of bounds Read

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45329
GHSA-W82J-7Q63-7PQM

Affected Products

Esp-Idf