Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-87961— ESP32-audioI2S 3.4.4 through 4.0.0 Heap-based Out-of-Bounds Read via Shadowed Length Parameter in read_ID3_Header

Quick assessment

Affected
schreibfaul1 ESP32-audioI2S
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

ESP32-audioI2S 版本 3.4.4 至 4.0.0 存在一个基于堆的越界读取漏洞。该漏洞位于 函数中,根源在于处理 ID3 同步歌词(Synchronized Lyrics)时,长度参数被遮蔽(shadowed length parameter)。攻击者可以通过构造带有超大帧大小声明的恶意 MP3 文件或 HTTP 音频流,使读取操作越过已分配缓冲区的边界,从而导致设备崩溃或泄露相邻的堆内存。

CVSS 7.1 · High

Possible ATT&CK Techniques 1 AI

T1204 · User Execution
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-87961

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
ESP32-audioI2S 3.4.4 through 4.0.0 Heap-based Out-of-Bounds Read via Shadowed Length Parameter in read_ID3_Header
Source: CVE Program / CVE List V5
Vulnerability Description
ESP32-audioI2S versions 3.4.4 through 4.0.0 contain a heap-based out-of-bounds read vulnerability in the read_ID3_Header function due to a shadowed length parameter in ID3 synchronized-lyrics processing. Attackers can craft malicious MP3 files or HTTP audio streams with oversized frame size declarations to read past allocated buffer boundaries, causing device crashes or exposing adjacent heap memory.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
schreibfaul1 ESP32-audioI2S 3.4.4 ~ 4.0.0 -

II. Public POCs for CVE-2026-87961

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-87961

登录查看更多情报信息。

Patches & Fixes for CVE-2026-87961 (2)

Vendor Advisories for CVE-2026-87961 (1)

Proof of Concept for CVE-2026-87961 (1)

Other References for CVE-2026-87961 (1)

Other References for CVE-2026-87961 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-87961

No comments yet


Leave a comment