


Perceptive Security
SOC/SIEM Consultancy

Unchecked unsigned integer overflow in buffer size calculation in schreibfaul1 ESP32-audioI2S 3.4.5 leads to undersized PSRAM buffer allocation. Subsequent norm…
Published:
27 July 2026 at 22:00:00
Alert date:
28 July 2026 at 20:07:40
Source:
nvd.nist.gov
Mobile & IoT, Zero-Day Vulnerabilities
CVE-2026-51259 affects schreibfaul1 ESP32-audioI2S version 3.4.5, an audio library for ESP32 microcontrollers. The vulnerability stems from an unchecked unsigned integer overflow in the buffer size calculation logic, leading to undersized PSRAM buffer allocation. When normal audio buffer read and write operations are subsequently performed, they cause heap out-of-bounds access and memory corruption. The impact ranges from denial of service to potential arbitrary code execution. The flaw resides in the Audio.cpp source file of the library. This is an embedded/IoT platform vulnerability affecting devices using this audio library. No patch version is referenced in the advisory. The vulnerability was disclosed via GitHub advisory and reported to NVD.
Technical details
Mitigation steps:
Affected products:
schreibfaul1 ESP32-audioI2S 3.4.5
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-51259
https://github.com/programmervuln/cveadvisory-/blob/main/CVE-2026-51259
https://github.com/schreibfaul1/ESP32-audioI2S/blob/master/src/Audio.cpp
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
