Intel

AIKIDO-2025-10232

espressif.esp-idf is vulnerable to Out-of-bounds Read

Out-of-bounds ReadCVE-2024-51569

75

High Risk

This Affects:

C++espressif.esp-idf
0.2.1 - 5.3.2
Fixed in 5.3.3

TL;DR

Affected versions of this package include a vulnerable release of Apache NimBLE, which suffers from an out-of-bounds read due to improper validation of the HCI Number Of Completed Packets field. This flaw may lead to invalid memory access when parsing HCI events, potentially reading from unintended areas of HCI transport memory. Exploitation requires a broken or malicious Bluetooth controller, which limits the practical impact, and the severity is therefore considered low.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

espressif.esp-idf is vulnerable to Out-of-bounds Read in versions 0.2.1 - 5.3.2.

How to fix this

Upgrade the espressif.esp-idf library to the patch version.