CVE-2026-45542 Details
Description
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the Security Scheme 2 (SRP6a) session-setup path of the protocomm component. The first-phase handler (handle_session_command0() in components/protocomm/src/security/security2.c) trusts the length of a client-supplied protobuf field for the SRP6a username and copies it into a buffer whose size is derived from a narrower destination type. The resulting truncation-versus-copy asymmetry corrupts the heap when an oversized value is supplied. This issue has been patched in versions 5.2.7, 5.3.6, 5.4.5, 5.5.5, and 6.0.1.
A heap buffer overflow vulnerability has been identified in the Espressif Internet of Things Development Framework (ESP-IDF) versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0. The issue resides in the Security Scheme 2 (SRP6a) session-setup path of the protocomm component. The vulnerability arises because the first-phase handler, 'handle_session_command0()', improperly trusts the length of a client-supplied protobuf field for the SRP6a username. This leads to a truncation-versus-copy asymmetry, allowing an oversized value to corrupt the heap. The flaw is only exploitable during Wi-Fi provisioning over the NimBLE Bluetooth Low Energy transport, when Security Scheme 2 is active.
Users are advised to upgrade to Espressif IDF versions 5.2.7, 5.3.6, 5.4.5, 5.5.5 or 6.0.1, where this vulnerability has been patched. If an immediate upgrade is not possible, consider restricting the provisioning window to avoid exposure during normal operation.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| espressif esp-idf | 5.2.6 5.3.5 5.4.4 5.5.4 6.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 11, 2026 | Initial Analysis | [email protected] |
| Jun 10, 2026 | New CVE Received | [email protected] |