What is CVE-2026-51259?
This CVE describes an unchecked unsigned integer overflow in buffer size calculation in schreibfaul1 ESP32-audioI2S version 3.4.5. The overflow leads to an undersized PSRAM buffer allocation, which can cause heap out-of-bounds access, memory corruption, denial of service, and potential code execution during normal audio operations.
Azərbaycanca: Bu CVE schreibfaul1 ESP32-audioI2S kitabxanasının 3.4.5 versiyasında tampon ölçüsü hesablanarkən yoxlanılmamış unsigned integer overflow zəifliyini təsvir edir. Zəiflik nəticəsində PSRAM üçün kiçik ölçülü tampon ayrılır ki, bu da yaddaş korrupsiyası, xidmət rəddi (denial of service) və potensial kod icrası (code execution) kimi təhlükələrə səbəb ola bilər.
Related CVEs
link basis: same weakness class CWE-190
FAQ2
Which version of ESP32-audioI2S is affected by CVE-2026-51259?
This vulnerability affects version 3.4.5 of the schreibfaul1 ESP32-audioI2S library.
What threats can arise from exploiting CVE-2026-51259?
This vulnerability can lead to memory corruption, denial of service, and potential code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.