ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the Security Scheme 2 (SRP6a) session-setup path of the protocomm component. The first-phase handler (handle_session_command0() in components/protocomm/src/security/security2.c) trusts the length of a client-supplied protobuf field for the SRP6a username and copies it into a buffer whose size is derived from a narrower destination type. The resulting truncation-versus-copy asymmetry corrupts the heap when an oversized value is supplied. This issue has been patched in versions 5.2.7, 5.3.6, 5.4.5, 5.5.5, and 6.0.1.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.2.6CPE matchmatch criteria | cpe:2.3:a:espressif:esp-idf:5.2.6:*:*:*:*:*:*:* | ||
5.3.5CPE matchmatch criteria | cpe:2.3:a:espressif:esp-idf:5.3.5:*:*:*:*:*:*:* | ||
5.4.4CPE matchmatch criteria | cpe:2.3:a:espressif:esp-idf:5.4.4:*:*:*:*:*:*:* | ||
5.5.4CPE matchmatch criteria | cpe:2.3:a:espressif:esp-idf:5.5.4:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:a:espressif:esp-idf:6.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.