CVE-2026-45542: ESF-IDF: Heap buffer overflow in protocomm Security2 over Bluetooth
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the Security Scheme 2 (SRP6a) session-setup path of the protocomm component. The first-phase handler (handlesessioncommand0() in components/protocomm/src/security/security2.c) trusts the length of a client-supplied protobuf field for the SRP6a username and copies it into a buffer whose size is derived from a narrower destination type. The resulting truncation-versus-copy asymmetry corrupts the heap when an oversized value is supplied. This issue has been patched in versions 5.2.7, 5.3.6, 5.4.5, 5.5.5, and 6.0.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ESF-IDFto a version that resolves this vulnerability.Fixed in 5.2.7 - Upgrade
Upgrade
ESF-IDFto a version that resolves this vulnerability.Fixed in 5.3.6 - Upgrade
Upgrade
ESF-IDFto a version that resolves this vulnerability.Fixed in 5.4.5 - Upgrade
Upgrade
ESF-IDFto a version that resolves this vulnerability.Fixed in 5.5.5 - Upgrade
Upgrade
ESF-IDFto a version that resolves this vulnerability.Fixed in 6.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45542?
The severity of CVE-2026-45542 is rated high with a score of 7.1.
What type of vulnerability is CVE-2026-45542?
CVE-2026-45542 is identified as a heap buffer overflow vulnerability.
How do I fix CVE-2026-45542?
To fix CVE-2026-45542, update to a secure version of Espressif ESP-IDF that addresses the heap buffer overflow.
Which versions of Espressif ESP-IDF are affected by CVE-2026-45542?
CVE-2026-45542 affects Espressif ESP-IDF versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0.
What component is impacted by CVE-2026-45542?
CVE-2026-45542 impacts the protocomm component of the Espressif ESP-IDF framework.