PT-2026-98227 · Espressif Systems · Esp-Idf
CVE-2026-81508
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v3.1
4.3
Medium
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
ESF-IDF version 5.5.5
ESF-IDF version 6.0.1
ESF-IDF version 6.1
Description
The BlueDroid A2DP sink function
btc a2dp sink handle inc media() reads a timestamp field from the received media buffer without first validating that the packet layout contains the field. A paired BR/EDR audio source within radio range can send a malformed A2DP media packet to a build with BlueDroid Classic Bluetooth and A2DP sink support enabled. This results in an out-of-bounds read into adjacent heap memory, leading to limited disclosure of heap contents. Arbitrary memory disclosure and code execution are not established.Recommendations
Update ESF-IDF version 5.5.5 to a newer version containing the fix.
Update ESF-IDF version 6.0.1 to a newer version containing the fix.
Update ESF-IDF version 6.1 to a newer version containing the fix.
As a temporary mitigation, restrict the use of the
btc a2dp sink handle inc media() function or disable A2DP sink support in BlueDroid Classic Bluetooth.Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Esp-Idf