Junglewise Threat Intelligence

CVE-2026-51259: schreibfaul1 ESP32-audioI2S integer overflow in audio buffer allocation

CVE-2026-51259 · Severity: info · CVSS 0 · Published 2026-07-28

Technologies: Schreibfaul1 ESP32-audioI2S. Vendors: Schreibfaul1.

Executive brief

ESP32-audioI2S is a popular library used by ESP32 microcontrollers to play audio files and internet radio streams. A flaw in how the library calculates memory requirements causes it to allocate a buffer that is much smaller than needed. When the device attempts to play any audio, it writes data past the end of this small buffer, leading to device crashes, permanent audio freezes, or potential unauthorized code execution.

Technical details

An integer overflow exists in `src/Audio.cpp` of ESP32-audioI2S v3.4.5 during audio buffer initialization. The library calculates the main audio buffer size using an expression like `UINT16_MAX * 10`, which overflows a 16-bit unsigned integer context, resulting in a truncated value significantly smaller than intended. This small value is passed to the PSRAM heap allocation function. Because the rest of the audio processing logic assumes the full intended size, subsequent read and write operations during audio playback result in heap out-of-bounds access. This can lead to memory corruption, denial of service (watchdog crashes), and potentially remote code execution depending on the PSRAM memory layout.

Affected products

  • schreibfaul1 ESP32-audioI2S 3.4.5

Timeline

  • 2026-07-28: disclosed: CVE-2026-51259 published to NVD

References

Related threats