ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, in the avrcvendormsg() function of the ESP-IDF BlueDroid AVRCP stack, the allocated buffer size was validated using AVRCMINCMDLEN (20 bytes). However, the actual fixed header data written before the vendor payload exceeds this value. This totals 29 bytes written before pmsg->pvendordata is copied. Using the old AVRCMINCMDLEN could allow an out-of-bounds write if vendorlen approaches the buffer limit. For commands where vendor_len is large, the original buffer allocation may be insufficient, causing writes beyond the allocated memory. This can lead to memory corruption, crashes, or other undefined behavior. The overflow could be larger when assertions are disabled.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68474.json",
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-787"
]
}{
"source": [
"CPE_STRING",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "5.1.6"
},
{
"last_affected": "5.1.6"
},
{
"introduced": "5.2.6"
},
{
"last_affected": "5.2.6"
},
{
"introduced": "5.3.4"
},
{
"last_affected": "5.3.4"
},
{
"introduced": "5.4.3"
},
{
"last_affected": "5.4.3"
},
{
"introduced": "5.5.1"
},
{
"last_affected": "5.5.1"
}
],
"cpe": [
"cpe:2.3:a:espressif:esp-idf:5.1.6:*:*:*:*:*:*:*",
"cpe:2.3:a:espressif:esp-idf:5.2.6:*:*:*:*:*:*:*",
"cpe:2.3:a:espressif:esp-idf:5.3.4:*:*:*:*:*:*:*",
"cpe:2.3:a:espressif:esp-idf:5.4.3:*:*:*:*:*:*:*",
"cpe:2.3:a:espressif:esp-idf:5.5.1:*:*:*:*:*:*:*"
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68474.json"
"2026-07-16T00:03:43Z"
[
{
"target": {
"file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c",
"function": "avrc_vendor_msg"
},
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2025-68474-0e49f32e",
"signature_version": "v1",
"source": "https://github.com/espressif/esp-idf/commit/0b0b59f2e19cb99dfa1b28c284d1c5c1d276a132",
"digest": {
"function_hash": "255425627612834306881528450754685714278",
"length": 1035.0
}
},
{
"target": {
"file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c",
"function": "avrc_vendor_msg"
},
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2025-68474-22c1343b",
"signature_version": "v1",
"source": "https://github.com/espressif/esp-idf/commit/b9ba1e29b65536ab4b670ac099585d09adce0376",
"digest": {
"function_hash": "255425627612834306881528450754685714278",
"length": 1035.0
}
},
{
"target": {
"file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c"
},
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2025-68474-28a57c8c",
"signature_version": "v1",
"source": "https://github.com/espressif/esp-idf/commit/0b0b59f2e19cb99dfa1b28c284d1c5c1d276a132",
"digest": {
"line_hashes": [
"26094655895741314426416138677682707102",
"245370479498947266080977233298622178019",
"251013883015043215954221422592931487959",
"258573252751419464751585958532335050931",
"330737948001457356911009114405955348395",
"247437857808796543569189147662398438192",
"53747660700991462447978860350387992829",
"276628350603158598146523546005776629868",
"222639883495691502687718164771534679037",
"270912222548511113450099842582500053606",
"23495127339189246816569044423631611276",
"191374441189109809603229966083545611741"
],
"threshold": 0.9
}
},
{
"target": {
"file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c",
"function": "avrc_vendor_msg"
},
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2025-68474-37ae2229",
"signature_version": "v1",
"source": "https://github.com/espressif/esp-idf/commit/8262ee807d5cd425f66304f703eeb3382fb888c0",
"digest": {
"function_hash": "255425627612834306881528450754685714278",
"length": 1035.0
}
},
{
"target": {
"file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c"
},
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2025-68474-5b24d08f",
"signature_version": "v1",
"source": "https://github.com/espressif/esp-idf/commit/565fa98d0cfd58102204c1cb636747e17ee59845",
"digest": {
"line_hashes": [
"26094655895741314426416138677682707102",
"245370479498947266080977233298622178019",
"251013883015043215954221422592931487959",
"258573252751419464751585958532335050931",
"330737948001457356911009114405955348395",
"247437857808796543569189147662398438192",
"53747660700991462447978860350387992829",
"276628350603158598146523546005776629868",
"222639883495691502687718164771534679037",
"270912222548511113450099842582500053606",
"23495127339189246816569044423631611276",
"191374441189109809603229966083545611741"
],
"threshold": 0.9
}
},
{
"target": {
"file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c",
"function": "avrc_vendor_msg"
},
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2025-68474-641bd726",
"signature_version": "v1",
"source": "https://github.com/espressif/esp-idf/commit/565fa98d0cfd58102204c1cb636747e17ee59845",
"digest": {
"function_hash": "255425627612834306881528450754685714278",
"length": 1035.0
}
},
{
"target": {
"file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c"
},
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2025-68474-7d976945",
"signature_version": "v1",
"source": "https://github.com/espressif/esp-idf/commit/8262ee807d5cd425f66304f703eeb3382fb888c0",
"digest": {
"line_hashes": [
"26094655895741314426416138677682707102",
"245370479498947266080977233298622178019",
"251013883015043215954221422592931487959",
"258573252751419464751585958532335050931",
"330737948001457356911009114405955348395",
"247437857808796543569189147662398438192",
"53747660700991462447978860350387992829",
"276628350603158598146523546005776629868",
"222639883495691502687718164771534679037",
"270912222548511113450099842582500053606",
"23495127339189246816569044423631611276",
"191374441189109809603229966083545611741"
],
"threshold": 0.9
}
},
{
"target": {
"file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c"
},
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2025-68474-8189254e",
"signature_version": "v1",
"source": "https://github.com/espressif/esp-idf/commit/b9ba1e29b65536ab4b670ac099585d09adce0376",
"digest": {
"line_hashes": [
"26094655895741314426416138677682707102",
"245370479498947266080977233298622178019",
"251013883015043215954221422592931487959",
"258573252751419464751585958532335050931",
"330737948001457356911009114405955348395",
"247437857808796543569189147662398438192",
"53747660700991462447978860350387992829",
"276628350603158598146523546005776629868",
"222639883495691502687718164771534679037",
"270912222548511113450099842582500053606",
"23495127339189246816569044423631611276",
"191374441189109809603229966083545611741"
],
"threshold": 0.9
}
},
{
"target": {
"file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c"
},
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2025-68474-b99e0966",
"signature_version": "v1",
"source": "https://github.com/espressif/esp-idf/commit/a6c1bc5e3e91ad1cb964ce2c178ee40a5d10a4a0",
"digest": {
"line_hashes": [
"26094655895741314426416138677682707102",
"245370479498947266080977233298622178019",
"251013883015043215954221422592931487959",
"258573252751419464751585958532335050931",
"330737948001457356911009114405955348395",
"247437857808796543569189147662398438192",
"53747660700991462447978860350387992829",
"276628350603158598146523546005776629868",
"222639883495691502687718164771534679037",
"270912222548511113450099842582500053606",
"23495127339189246816569044423631611276",
"191374441189109809603229966083545611741"
],
"threshold": 0.9
}
},
{
"target": {
"file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c",
"function": "avrc_vendor_msg"
},
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2025-68474-d22ddd66",
"signature_version": "v1",
"source": "https://github.com/espressif/esp-idf/commit/a6c1bc5e3e91ad1cb964ce2c178ee40a5d10a4a0",
"digest": {
"function_hash": "255425627612834306881528450754685714278",
"length": 1035.0
}
},
{
"target": {
"file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c"
},
"deprecated": false,
"signature_type": "Line",
"id": "CVE-2025-68474-d24e86b7",
"signature_version": "v1",
"source": "https://github.com/espressif/esp-idf/commit/aa0e3d75db995b7137b55349fc92ee684b47092d",
"digest": {
"line_hashes": [
"26094655895741314426416138677682707102",
"245370479498947266080977233298622178019",
"251013883015043215954221422592931487959",
"258573252751419464751585958532335050931",
"330737948001457356911009114405955348395",
"247437857808796543569189147662398438192",
"53747660700991462447978860350387992829",
"276628350603158598146523546005776629868",
"222639883495691502687718164771534679037",
"270912222548511113450099842582500053606",
"23495127339189246816569044423631611276",
"191374441189109809603229966083545611741"
],
"threshold": 0.9
}
},
{
"target": {
"file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c",
"function": "avrc_vendor_msg"
},
"deprecated": false,
"signature_type": "Function",
"id": "CVE-2025-68474-d836cc74",
"signature_version": "v1",
"source": "https://github.com/espressif/esp-idf/commit/aa0e3d75db995b7137b55349fc92ee684b47092d",
"digest": {
"function_hash": "255425627612834306881528450754685714278",
"length": 1035.0
}
}
]