


Perceptive Security
SOC/SIEM Consultancy

schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in UnpackFrameHeader(). Multiple attacker-controlled index parameters are used to access s…
Published:
26 July 2026 at 22:00:00
Alert date:
27 July 2026 at 20:03:54
Source:
nvd.nist.gov
Mobile & IoT, Emerging Technologies
A buffer overflow vulnerability has been identified in schreibfaul1 ESP32-audioI2S version 3.4.5, specifically within the UnpackFrameHeader() function. The vulnerability arises because multiple attacker-controlled index parameters are used to access static and heap table arrays without proper range validation or boundary checks. Invalid index values can lead to out-of-bounds memory writes and heap buffer overflow conditions. This type of vulnerability could potentially allow an attacker to execute arbitrary code or cause a denial of service on affected ESP32 devices. The issue is documented in the mp3_decoder.cpp source file of the library. ESP32-audioI2S is a widely used audio library for ESP32 microcontrollers, making this vulnerability relevant to IoT and embedded systems. The vulnerability has been assigned CVE-2026-51244 and is tracked on the NVD. No patch version has been explicitly mentioned in the article.
Technical details
Mitigation steps:
Affected products:
schreibfaul1 ESP32-audioI2S 3.4.5
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-51244
https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51244
https://github.com/schreibfaul1/ESP32-audioI2S/blob/master/src/mp3_decoder/mp3_decoder.cpp
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
