What is CVE-2026-51260?
This critical vulnerability arises from an unsafe memcpy operation in the AudioBuffer::writeSpace() function of the ESP32-audioI2S 3.4.5 library, leading to a remote heap buffer overflow. It is recommended to update the library to mitigate the risk of memory corruption on affected devices.
Azərbaycanca: Bu kritik zəiflik ESP32-audioI2S 3.4.5 kitabxanasında AudioBuffer::writeSpace() funksiyasında təhlükəsiz olmayan memcpy əməliyyatı nəticəsində yaranır və uzaqdan heap buffer overflow-a səbəb olur. Təsirə məruz qalan cihazlarda yaddaş pozuntusu riskini aradan qaldırmaq üçün kitabxananı yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: schreibfaul1
FAQ2
Which version of the ESP32-audioI2S library is affected by CVE-2026-51260?
This critical vulnerability specifically exists in version 3.4.5 of the ESP32-audioI2S library.
What is the root cause of the CVE-2026-51260 vulnerability?
The vulnerability is caused by an unsafe memcpy operation in the AudioBuffer::writeSpace() function, leading to a remote heap buffer overflow.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.