Executive brief
A vulnerability exists in the ESP32-audioI2S library, which is used by ESP32 microcontrollers to play audio files. By providing a specially crafted MP3 file, an attacker can cause the device to crash or potentially run unauthorized code. This could lead to a permanent service outage or allow an attacker to gain control over the connected hardware.
Technical details
A heap buffer overflow exists in the UnpackFrameHeader() function within the MP3 decoder of ESP32-audioI2S version 3.4.5. The vulnerability is caused by the lack of boundary validation for m_MPEGVersion and srIdx values parsed directly from the MP3 bitstream. These unvalidated indices are used to access the static sfBandTable, resulting in out-of-bounds memory access. An attacker can provide a malicious MP3 file that, when processed, leads to corrupted pointers and subsequent out-of-bounds heap writes, potentially allowing for arbitrary code execution or a denial-of-service (DoS) on the ESP32 hardware.
Affected products
- schreibfaul1 ESP32-audioI2S 3.4.5
Timeline
- 2026-07-27: advisory: CVE published by NVD/MITRE