Executive brief
Espressif ESP-IDF is a development framework used to build software for Internet of Things (IoT) devices. A security flaw in the device setup component allows an attacker within Bluetooth range to crash the device or corrupt its memory by sending a specially crafted username during the initial connection. This can prevent the device from being configured or cause it to stop functioning, potentially impacting operations that rely on these connected devices.
Technical details
A heap buffer overflow exists in the handle_session_command0() function within components/protocomm/src/security/security2.c of the Espressif IoT Development Framework (ESP-IDF). The vulnerability is caused by a truncation-versus-copy asymmetry where the code trusts a client-supplied protobuf field length for the SRP6a username and copies it into a buffer sized based on a narrower destination type. An unauthenticated attacker within Bluetooth Low Energy (BLE) range can exploit this during the provisioning phase to corrupt the heap, leading to a device crash or denial of service. The issue specifically affects devices using the NimBLE transport with Security Scheme 2. Patches are available in versions 5.2.7, 5.3.6, 5.4.5, 5.5.5, and 6.0.1.
Affected products
- Espressif Systems ESP-IDF 5.2.6, 5.3.5, 5.4.4, 5.5.4, 6.0
Timeline
- 2026-05-18: advisory: GitHub Security Advisory published by Espressif
- 2026-06-10: disclosed: CVE published to NVD
References
- https://github.com/espressif/esp-idf/commit/0ea58d79845ad674d0358d5de246015a68c4cb4f
- https://github.com/espressif/esp-idf/commit/56c3e385611e63162d0f2f8504ac4ae2ccfccef0
- https://github.com/espressif/esp-idf/commit/71eb2dbe6aaef830719ecac8edf409e2992b64b2
- https://github.com/espressif/esp-idf/commit/9b4cacf9cbc69379972de6a2247fcf5af9240961
- https://github.com/espressif/esp-idf/commit/a2f4554f10ba075c98cbc67464db096ba32497cf
- https://github.com/espressif/esp-idf/commit/f5d24a7e919bc5f447091479656b86da6762a103
- https://github.com/espressif/esp-idf/security/advisories/GHSA-9r76-858f-v6jh