CVE-2026-25507: ESF-IDF Has Use-after-free Vulnerability in BLE Provisioning

Published Feb 4, 2026
·
Updated

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, a use-after-free vulnerability was reported in the BLE provisioning transport (protocommble) layer. The issue can be triggered by a remote BLE client while the device is in provisioning mode. The vulnerability occurred when provisioning was stopped with keepbleon = true. In this configuration, internal protocommble state and GATT metadata were freed while the BLE stack and GATT services remained active. Subsequent BLE read or write callbacks dereferenced freed memory, allowing a connected or newly connected client to trigger invalid memory acces. This issue has been patched in versions 5.5.3, 5.4.4, 5.3.5, 5.2.7, and 5.1.7.

Affected Software

6 affected components
Espressif ESF-IDF>=5.1.6<5.5.2
Espressif ESP-IDF=5.1.6
Espressif ESP-IDF=5.2.6
Espressif ESP-IDF=5.3.4
Espressif ESP-IDF=5.4.3
Espressif ESP-IDF=5.5.2

Event History

Feb 4, 2026
CVE Published
via MITRE·05:58 PM
Data Sourced
via MITRE·05:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-25507?

CVE-2026-25507 has been classified as a high severity vulnerability due to its potential to cause a use-after-free condition in BLE provisioning.

2

How do I fix CVE-2026-25507?

To fix CVE-2026-25507, upgrade to versions of ESF-IDF that are above 5.5.2, specifically 5.6.0 or later, as they contain patches for this vulnerability.

3

What versions of ESF-IDF are affected by CVE-2026-25507?

CVE-2026-25507 affects ESF-IDF versions 5.1.6 to 5.5.2 inclusive.

4

What type of vulnerability is CVE-2026-25507?

CVE-2026-25507 is identified as a use-after-free vulnerability within the BLE provisioning layer of ESF-IDF.

5

Can CVE-2026-25507 lead to remote code execution?

Yes, CVE-2026-25507 can potentially lead to remote code execution if exploited by attackers due to the misuse of freed memory.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203