PT-2026-98227 · Espressif Systems · Esp-Idf

CVE-2026-81508

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v3.1

4.3

Medium

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions ESF-IDF version 5.5.5 ESF-IDF version 6.0.1 ESF-IDF version 6.1
Description The BlueDroid A2DP sink function btc a2dp sink handle inc media() reads a timestamp field from the received media buffer without first validating that the packet layout contains the field. A paired BR/EDR audio source within radio range can send a malformed A2DP media packet to a build with BlueDroid Classic Bluetooth and A2DP sink support enabled. This results in an out-of-bounds read into adjacent heap memory, leading to limited disclosure of heap contents. Arbitrary memory disclosure and code execution are not established.
Recommendations Update ESF-IDF version 5.5.5 to a newer version containing the fix. Update ESF-IDF version 6.0.1 to a newer version containing the fix. Update ESF-IDF version 6.1 to a newer version containing the fix. As a temporary mitigation, restrict the use of the btc a2dp sink handle inc media() function or disable A2DP sink support in BlueDroid Classic Bluetooth.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81508
GHSA-XCPR-5MQP-9QVV

Affected Products

Esp-Idf