PT-2026-57221 · Espressif Systems · Esp-Idf
CVE-2026-55687
·
Published
2026-07-10
·
Updated
2026-07-10
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ESF-IDF versions prior to 6.0.2
ESF-IDF versions prior to 5.5.5
ESF-IDF versions prior to 5.4.5
ESF-IDF versions prior to 5.3.6
Description
An out-of-bounds write exists in the
jpeg parse dqt marker() function within components/esp driver jpeg/jpeg parse marker.c. This occurs because the DQT marker Tq nibble, which can be controlled by an attacker, is used as an index for the qt tbl array without verifying that it falls within the 0..3 range. Consequently, malformed JPEG input can corrupt stack memory, leading to a denial of service.Recommendations
Update to version 6.0.2.
Update to version 5.5.5.
Update to version 5.4.5.
Update to version 5.3.6.
Exploit
Fix
DoS
Memory Corruption
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Esp-Idf