IoT
CVE-2026-51259
9.8
Critical
EPSS n/aJul 29, 2026
Integer overflow in ESP32-audioI2S causes PSRAM buffer OOB, enabling DoS/RCE
This CVE has been withdrawn. NVD marks this identifier as Rejected, which means it was a duplicate or turned out not to be a vulnerability. The analysis below is kept for reference only — do not act on it.
executive summary
technical analysis
affected
ESP32-audioI2S 3.4.5ESP32-based devices using PSRAM and audioI2SProducts built on ESP-IDF with this library
impact
Unsigned integer overflow yields undersized PSRAM allocation; heap out-of-bounds leads to memory corruption, remote DoS and potential arbitrary code execution via audio I2S flows.
action required
Immediate action required
how to fix
Remediation steps are tailored for users whose stack is affected. Add this technology to your stack to see the fix checklist.
references