CVE-2026-81508: ESF-IDF: Heap Out-of-Bounds Read in Bluedroid A2DP Sink Media Packet Processing

Published Sep 24, 2026
·
Updated

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.5, 6.0.1, and 6.1, the BlueDroid A2DP sink function btca2dpsinkhandleincmedia() reads a timestamp field from the received media buffer before validating that the packet layout contains the field. A paired BR/EDR audio source within radio range can send a malformed A2DP media packet to a build with BlueDroid Classic Bluetooth and A2DP sink support enabled, causing an out-of-bounds read into adjacent heap memory and limited disclosure of heap contents. Arbitrary memory disclosure and code execution are not established.

Affected Software

1 affected component
Espressif ESP-IDF=5.5.5, =6.0.1, =6.1

Event History

Sep 24, 2026
CVE Published
via MITRE·05:52 PM
Data Sourced
via MITRE·05:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which devices are exposed to this issue?

Devices built with affected ESP-IDF versions are exposed only if they enable BlueDroid Classic Bluetooth and A2DP sink support. The attack source must be a paired BR/EDR audio device within Bluetooth radio range.

2

What does an attacker need to exploit it?

An attacker needs to operate a paired BR/EDR audio source within radio range and send a malformed A2DP media packet. No additional privileges or user interaction are required.

3

What is the demonstrated impact?

The malformed packet can cause an out-of-bounds read of adjacent heap memory, resulting in limited disclosure of heap contents. Arbitrary memory disclosure and code execution have not been established.

4

What can be done if updating is not immediately possible?

Disable BlueDroid Classic Bluetooth or A2DP sink support in affected builds where those features are not required. Limiting pairing to trusted BR/EDR audio sources also reduces exposure, since exploitation requires a paired device.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203