PT-2026-48354 · Espressif Systems · Esp-Idf
CVE-2026-46532
·
Published
2026-06-10
·
Updated
2026-06-11
CVSS v3.1
4.6
Medium
| Vector | AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
ESF-IDF version 5.2.6
ESF-IDF version 5.3.5
ESF-IDF version 5.4.4
ESF-IDF version 5.5.3
ESF-IDF version 6.0
Description
An out-of-bounds read exists in the BlueDroid AVRCP vendor-command parser within the
avrc pars vendor cmd() function located in components/bt/host/bluedroid/stack/avrc/avrc pars tg.c. An out-of-bounds read occurs when a program reads data past the end or fully outside the boundary of the intended buffer.Recommendations
Update version 5.2.6 to 5.2.7
Update version 5.3.5 to 5.3.6
Update version 5.4.4 to 5.4.5
Update version 5.5.3 to 5.5.4
Update version 6.0 to 6.0.1
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Esp-Idf