CVE-2026-81508: Espressif Esp-Idf

Medium severity, CVSS 4.3. EPSS: 0.2% chance of exploitation in the next 30 days.

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.5, 6.0.1, and 6.1, the BlueDroid A2DP sink function btc_a2dp_sink_handle_inc_media() reads a timestamp field from the received media buffer before validating that the packet layout contains the field. A paired BR/EDR audio source within radio range can send a malformed A2DP media packet to a build with BlueDroid Classic Bluetooth and A2DP sink support enabled, causing an out-of-bounds read into adjacent heap memory and limited disclosure of heap contents. Arbitrary memory disclosure and code execution are not established.

Affected products

  • Espressif Esp-Idf: version 6.1 only; version 6.0.1 only; version 5.5.5 only

Published 2026-09-24. Last modified 2026-09-25.