CVE-2026-81508 Details
Description
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.5, 6.0.1, and 6.1, the BlueDroid A2DP sink function btc_a2dp_sink_handle_inc_media() reads a timestamp field from the received media buffer before validating that the packet layout contains the field. A paired BR/EDR audio source within radio range can send a malformed A2DP media packet to a build with BlueDroid Classic Bluetooth and A2DP sink support enabled, causing an out-of-bounds read into adjacent heap memory and limited disclosure of heap contents. Arbitrary memory disclosure and code execution are not established.
A heap out-of-bounds read vulnerability has been identified in the BlueDroid A2DP sink media packet handler within the Espressif Internet of Things Development Framework (ESP-IDF) versions 5.5.5, 6.0.1, and 6.1. This vulnerability allows a paired BR/EDR audio source to send a malformed A2DP media packet, causing the handler to read a timestamp field from the media buffer before validating the packet layout. As a result, the read operation can extend beyond the intended buffer boundary into adjacent heap memory, leading to a limited disclosure of heap contents. The vulnerability is present in builds with BlueDroid Classic Bluetooth and A2DP sink support enabled.
Users can upgrade to Espressif IDF versions 6.1.1, 6.0.2, or 5.5.6 to address this vulnerability. The fix is also available on the 'master' branch. For products that do not require A2DP sink or Classic Bluetooth, these features can be disabled.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026CISA-ADP
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Espressif ESP-IDF | 6.1 6.0.1 (semver) 5.5.5 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | CVE Modified | CISA-ADP |
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion