CVE-2026-51268: schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the host parsing logic.
schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the host parsing logic. The dismantle_host() function parses untrusted host and URL input, and subsequent code uses clone_from() to copy parsed host, request host, extension and query_string segments into fixed heap buffers without boundary checking.
Security readout for executives and security teams
Plain-English summary
ESP32-audioI2S 3.4.5 may mishandle overly long host or URL data, overflowing memory allocated on the heap. A remotely supplied input could corrupt an affected device’s memory without authentication or user interaction. The supplied CVSS rating indicates potentially severe confidentiality, integrity, and availability consequences.
Executive priority
Treat as an urgent investigation and remediation item for products using version 3.4.5, especially remotely reachable devices. The technical severity is critical, but fleet-wide business risk depends on actual library deployment and attacker control of URL inputs. No active exploitation is established by the supplied evidence.
Technical view
The dismantle_host() path parses untrusted host and URL input. Later clone_from() operations copy host, request-host, extension, and query-string segments into fixed-size heap buffers without bounds checking, producing a CWE-122 heap-based buffer overflow. The supplied CVSS v3.1 score is 9.8 with network reachability, low complexity, and no privileges or interaction required.
Likely exposure
Exposure is most likely where firmware incorporates ESP32-audioI2S 3.4.5 and processes attacker-controlled host or URL values. The supplied structured affected-product fields are unspecified, so asset owners must confirm library inclusion, deployed version, input reachability, and whether surrounding code constrains lengths.
Exploitation context
The source bundle does not report CISA KEV inclusion or provide evidence of active exploitation. It describes a remotely reachable, unauthenticated, low-complexity condition, but successful real-world impact may depend on firmware integration, memory layout, compiler protections, and input handling.
Researcher notes
The key evidence is an unchecked copy chain following host and URL segmentation. Review every destination associated with host, request host, extension, and query_string, including allocation assumptions and termination behavior. The bundle identifies version 3.4.5, but its structured vendor/product fields are unspecified and it names no fixed version.
Mitigation direction
Inventory firmware and source dependencies for ESP32-audioI2S 3.4.5.
Check upstream vendor guidance for a corrected release or approved patch.
Restrict untrusted host and URL input from reaching affected parsing logic.
Apply strict length validation before affected fields are parsed or copied.
Prioritize internet-reachable or remotely controlled devices for remediation.
Validation and detection
Confirm the exact ESP32-audioI2S version embedded in each firmware image.
Trace whether remote inputs can reach dismantle_host() and subsequent clone_from() calls.
Review destination buffer sizes and all upstream length checks.
Test corrected builds with oversized inputs in an isolated, authorized environment.
Verify deployed firmware matches the remediated build and retains input limits.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-122: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
1CVSS vectors
3Timeline events
1ADP providers
3Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: total
CVSS vector scores
1 official score
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-122 · source CWE mapping
Heap-based Buffer Overflow
Heap-based Buffer Overflow represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.