CVE-2025-68474

Source
https://cve.org/CVERecord?id=CVE-2025-68474
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68474.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-68474
Aliases
  • GHSA-43gh-7r4f-qp57
Published
2025-12-26T23:57:54.853Z
Modified
2026-07-16T00:03:43.986902Z
Severity
  • 6.1 (Medium) CVSS_V4 - CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:L CVSS Calculator
Summary
ESF-IDF Has Out-of-Bounds Write in ESP32 Bluetooth AVRCP Vendor Command Handling
Details

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, in the avrcvendormsg() function of the ESP-IDF BlueDroid AVRCP stack, the allocated buffer size was validated using AVRCMINCMDLEN (20 bytes). However, the actual fixed header data written before the vendor payload exceeds this value. This totals 29 bytes written before pmsg->pvendordata is copied. Using the old AVRCMINCMDLEN could allow an out-of-bounds write if vendorlen approaches the buffer limit. For commands where vendor_len is large, the original buffer allocation may be insufficient, causing writes beyond the allocated memory. This can lead to memory corruption, crashes, or other undefined behavior. The overflow could be larger when assertions are disabled.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/68xxx/CVE-2025-68474.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-787"
    ]
}
References

Affected packages

Git / github.com/espressif/esp-idf

Affected ranges

Type
GIT
Repo
https://github.com/espressif/esp-idf
Events
Database specific
{
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "5.1.6"
        },
        {
            "last_affected": "5.1.6"
        },
        {
            "introduced": "5.2.6"
        },
        {
            "last_affected": "5.2.6"
        },
        {
            "introduced": "5.3.4"
        },
        {
            "last_affected": "5.3.4"
        },
        {
            "introduced": "5.4.3"
        },
        {
            "last_affected": "5.4.3"
        },
        {
            "introduced": "5.5.1"
        },
        {
            "last_affected": "5.5.1"
        }
    ],
    "cpe": [
        "cpe:2.3:a:espressif:esp-idf:5.1.6:*:*:*:*:*:*:*",
        "cpe:2.3:a:espressif:esp-idf:5.2.6:*:*:*:*:*:*:*",
        "cpe:2.3:a:espressif:esp-idf:5.3.4:*:*:*:*:*:*:*",
        "cpe:2.3:a:espressif:esp-idf:5.4.3:*:*:*:*:*:*:*",
        "cpe:2.3:a:espressif:esp-idf:5.5.1:*:*:*:*:*:*:*"
    ]
}

Affected versions

5.*
5.1.6
5.2.6
5.3.4
5.4.3
5.5.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-68474.json"
vanir_signatures_modified
"2026-07-16T00:03:43Z"
vanir_signatures
[
    {
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c",
            "function": "avrc_vendor_msg"
        },
        "deprecated": false,
        "signature_type": "Function",
        "id": "CVE-2025-68474-0e49f32e",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/0b0b59f2e19cb99dfa1b28c284d1c5c1d276a132",
        "digest": {
            "function_hash": "255425627612834306881528450754685714278",
            "length": 1035.0
        }
    },
    {
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c",
            "function": "avrc_vendor_msg"
        },
        "deprecated": false,
        "signature_type": "Function",
        "id": "CVE-2025-68474-22c1343b",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/b9ba1e29b65536ab4b670ac099585d09adce0376",
        "digest": {
            "function_hash": "255425627612834306881528450754685714278",
            "length": 1035.0
        }
    },
    {
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c"
        },
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2025-68474-28a57c8c",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/0b0b59f2e19cb99dfa1b28c284d1c5c1d276a132",
        "digest": {
            "line_hashes": [
                "26094655895741314426416138677682707102",
                "245370479498947266080977233298622178019",
                "251013883015043215954221422592931487959",
                "258573252751419464751585958532335050931",
                "330737948001457356911009114405955348395",
                "247437857808796543569189147662398438192",
                "53747660700991462447978860350387992829",
                "276628350603158598146523546005776629868",
                "222639883495691502687718164771534679037",
                "270912222548511113450099842582500053606",
                "23495127339189246816569044423631611276",
                "191374441189109809603229966083545611741"
            ],
            "threshold": 0.9
        }
    },
    {
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c",
            "function": "avrc_vendor_msg"
        },
        "deprecated": false,
        "signature_type": "Function",
        "id": "CVE-2025-68474-37ae2229",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/8262ee807d5cd425f66304f703eeb3382fb888c0",
        "digest": {
            "function_hash": "255425627612834306881528450754685714278",
            "length": 1035.0
        }
    },
    {
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c"
        },
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2025-68474-5b24d08f",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/565fa98d0cfd58102204c1cb636747e17ee59845",
        "digest": {
            "line_hashes": [
                "26094655895741314426416138677682707102",
                "245370479498947266080977233298622178019",
                "251013883015043215954221422592931487959",
                "258573252751419464751585958532335050931",
                "330737948001457356911009114405955348395",
                "247437857808796543569189147662398438192",
                "53747660700991462447978860350387992829",
                "276628350603158598146523546005776629868",
                "222639883495691502687718164771534679037",
                "270912222548511113450099842582500053606",
                "23495127339189246816569044423631611276",
                "191374441189109809603229966083545611741"
            ],
            "threshold": 0.9
        }
    },
    {
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c",
            "function": "avrc_vendor_msg"
        },
        "deprecated": false,
        "signature_type": "Function",
        "id": "CVE-2025-68474-641bd726",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/565fa98d0cfd58102204c1cb636747e17ee59845",
        "digest": {
            "function_hash": "255425627612834306881528450754685714278",
            "length": 1035.0
        }
    },
    {
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c"
        },
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2025-68474-7d976945",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/8262ee807d5cd425f66304f703eeb3382fb888c0",
        "digest": {
            "line_hashes": [
                "26094655895741314426416138677682707102",
                "245370479498947266080977233298622178019",
                "251013883015043215954221422592931487959",
                "258573252751419464751585958532335050931",
                "330737948001457356911009114405955348395",
                "247437857808796543569189147662398438192",
                "53747660700991462447978860350387992829",
                "276628350603158598146523546005776629868",
                "222639883495691502687718164771534679037",
                "270912222548511113450099842582500053606",
                "23495127339189246816569044423631611276",
                "191374441189109809603229966083545611741"
            ],
            "threshold": 0.9
        }
    },
    {
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c"
        },
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2025-68474-8189254e",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/b9ba1e29b65536ab4b670ac099585d09adce0376",
        "digest": {
            "line_hashes": [
                "26094655895741314426416138677682707102",
                "245370479498947266080977233298622178019",
                "251013883015043215954221422592931487959",
                "258573252751419464751585958532335050931",
                "330737948001457356911009114405955348395",
                "247437857808796543569189147662398438192",
                "53747660700991462447978860350387992829",
                "276628350603158598146523546005776629868",
                "222639883495691502687718164771534679037",
                "270912222548511113450099842582500053606",
                "23495127339189246816569044423631611276",
                "191374441189109809603229966083545611741"
            ],
            "threshold": 0.9
        }
    },
    {
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c"
        },
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2025-68474-b99e0966",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/a6c1bc5e3e91ad1cb964ce2c178ee40a5d10a4a0",
        "digest": {
            "line_hashes": [
                "26094655895741314426416138677682707102",
                "245370479498947266080977233298622178019",
                "251013883015043215954221422592931487959",
                "258573252751419464751585958532335050931",
                "330737948001457356911009114405955348395",
                "247437857808796543569189147662398438192",
                "53747660700991462447978860350387992829",
                "276628350603158598146523546005776629868",
                "222639883495691502687718164771534679037",
                "270912222548511113450099842582500053606",
                "23495127339189246816569044423631611276",
                "191374441189109809603229966083545611741"
            ],
            "threshold": 0.9
        }
    },
    {
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c",
            "function": "avrc_vendor_msg"
        },
        "deprecated": false,
        "signature_type": "Function",
        "id": "CVE-2025-68474-d22ddd66",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/a6c1bc5e3e91ad1cb964ce2c178ee40a5d10a4a0",
        "digest": {
            "function_hash": "255425627612834306881528450754685714278",
            "length": 1035.0
        }
    },
    {
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c"
        },
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2025-68474-d24e86b7",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/aa0e3d75db995b7137b55349fc92ee684b47092d",
        "digest": {
            "line_hashes": [
                "26094655895741314426416138677682707102",
                "245370479498947266080977233298622178019",
                "251013883015043215954221422592931487959",
                "258573252751419464751585958532335050931",
                "330737948001457356911009114405955348395",
                "247437857808796543569189147662398438192",
                "53747660700991462447978860350387992829",
                "276628350603158598146523546005776629868",
                "222639883495691502687718164771534679037",
                "270912222548511113450099842582500053606",
                "23495127339189246816569044423631611276",
                "191374441189109809603229966083545611741"
            ],
            "threshold": 0.9
        }
    },
    {
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_opt.c",
            "function": "avrc_vendor_msg"
        },
        "deprecated": false,
        "signature_type": "Function",
        "id": "CVE-2025-68474-d836cc74",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/aa0e3d75db995b7137b55349fc92ee684b47092d",
        "digest": {
            "function_hash": "255425627612834306881528450754685714278",
            "length": 1035.0
        }
    }
]