CVE Watcher
Sitemap Privacy Security.txt Open CVE Console

Shareable CVE page

CVE-2026-45542

This is the local share page for this CVE/source combination.

CVE-2026-45542

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the Security Scheme 2 (SRP6a) session-setup path of the protocomm component. The first-phase handler (handle_session_command0() in components/protocomm/src/security/security2.c) trusts the length of a client-supplied protobuf field for the SRP6a username and copies it into a buffer whose size is derived from a narrower destination type. The resulting truncation-versus-copy asymmetry corrupts the heap when an oversized value is supplied. This issue has been patched in versions 5.2.7, 5.3.6, 5.4.5, 5.5.5, and 6.0.1.

high
SourceCVE List v5 CVSS7.1 Severityhigh Published2026-06-10 EPSSn/a
Open in CVE Console
Vector and technical detailsCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H