What is CVE-2026-51251?
CVE-2026-51251 is a buffer overflow vulnerability in the MP3Decoder::decode() function of Schreibfaul1 ESP32-audioI2S library version 3.4.5. It occurs due to missing size validation on untrusted mainDataBegin and nSlots values during MP3 processing. Users should update to the latest version or restrict MP3 processing to trusted sources.
Azərbaycanca: CVE-2026-51251, Schreibfaul1 ESP32-audioI2S kitabxanasının 3.4.5 versiyasında MP3Decoder::decode() funksiyasında aşkarlanmış buffer overflow zəifliyidir. Bu zəiflik, MP3 fayllarını emal edərkən etibarsız mainDataBegin və nSlots dəyərlərinin ölçü yoxlaması olmadan istifadə edilməsindən qaynaqlanır. İstifadəçilər kitabxananı ən son versiyaya yeniləməli və ya MP3 emalını etibarlı mənbələrlə məhdudlaşdırmalıdır.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: schreibfaul1
FAQ2
Which version of the Schreibfaul1 ESP32-audioI2S library is affected by CVE-2026-51251?
This vulnerability was identified in version 3.4.5 of the library.
What is the root cause of CVE-2026-51251?
The vulnerability occurs due to missing size validation on the mainDataBegin and nSlots values when processing MP3 files.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.