top of page
perceptive_background_267k.jpg

Unchecked unsigned integer overflow in buffer size calculation in schreibfaul1 ESP32-audioI2S 3.4.5 leads to undersized PSRAM buffer allocation. Subsequent norm…

Published:

27 July 2026 at 22:00:00

Alert date:

28 July 2026 at 20:07:40

Source:

nvd.nist.gov

Click to open the original link from this advisory

Mobile & IoT, Zero-Day Vulnerabilities

CVE-2026-51259 affects schreibfaul1 ESP32-audioI2S version 3.4.5, an audio library for ESP32 microcontrollers. The vulnerability stems from an unchecked unsigned integer overflow in the buffer size calculation logic, leading to undersized PSRAM buffer allocation. When normal audio buffer read and write operations are subsequently performed, they cause heap out-of-bounds access and memory corruption. The impact ranges from denial of service to potential arbitrary code execution. The flaw resides in the Audio.cpp source file of the library. This is an embedded/IoT platform vulnerability affecting devices using this audio library. No patch version is referenced in the advisory. The vulnerability was disclosed via GitHub advisory and reported to NVD.

Technical details

Mitigation steps:

Affected products:

schreibfaul1 ESP32-audioI2S 3.4.5

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page