CVE-2026-46532

Source
https://cve.org/CVERecord?id=CVE-2026-46532
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46532.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-46532
Aliases
  • GHSA-3pp8-42fh-3j3c
Published
2026-06-10T00:35:30Z
Modified
2026-08-12T16:09:38Z
Severity
  • 4.6 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L CVSS Calculator
Summary
ESF-IDF: Heap Out-of-Bounds Read in Bluedroid AVRCP Target Parser
Details

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0, an out-of-bounds read exists in the BlueDroid AVRCP vendor-command parser (avrc_pars_vendor_cmd() in components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c). This issue has been patched in versions 5.2.7, 5.3.6, 5.4.5, 5.5.4, and 6.0.1.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-125"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46532.json"
}
References

Affected packages

Git / github.com/espressif/esp-idf

Affected ranges

Type
GIT
Repo
https://github.com/espressif/esp-idf
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:espressif:esp-idf:5.2.6:*:*:*:*:*:*:*",
        "cpe:2.3:a:espressif:esp-idf:5.3.5:*:*:*:*:*:*:*",
        "cpe:2.3:a:espressif:esp-idf:5.4.4:*:*:*:*:*:*:*",
        "cpe:2.3:a:espressif:esp-idf:5.5.3:*:*:*:*:*:*:*",
        "cpe:2.3:a:espressif:esp-idf:6.0:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "5.2.6"
        },
        {
            "last_affected": "5.2.6"
        },
        {
            "introduced": "5.3.5"
        },
        {
            "last_affected": "5.3.5"
        },
        {
            "introduced": "5.4.4"
        },
        {
            "last_affected": "5.4.4"
        },
        {
            "introduced": "5.5.3"
        },
        {
            "last_affected": "5.5.3"
        },
        {
            "introduced": "6.0"
        },
        {
            "last_affected": "6.0"
        }
    ],
    "source": [
        "CPE_STRING",
        "REFERENCES"
    ]
}

Affected versions

5.*
5.2.6
5.3.5
5.4.4
5.5.3
6.*
6.0
= 5.*
= 5.2.6
= 5.3.5
= 5.4.4
= 5.5.3
= 6.*
= 6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46532.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "319855188188705565088376373846457537461",
            "length": 5740
        },
        "id": "CVE-2026-46532-16af42b3",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/b0959b5ab1dc60398a916c80f14b1816780c801e",
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c",
            "function": "avrc_pars_vendor_cmd"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "319855188188705565088376373846457537461",
            "length": 5740
        },
        "id": "CVE-2026-46532-2c9a1259",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/60f9362f83a05942069532f357c234cd5e5d4302",
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c",
            "function": "avrc_pars_vendor_cmd"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "319855188188705565088376373846457537461",
            "length": 5740
        },
        "id": "CVE-2026-46532-327c346b",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/8746e5f7e762ead84d2902edec34d84cdd701b2b",
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c",
            "function": "avrc_pars_vendor_cmd"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "319855188188705565088376373846457537461",
            "length": 5740
        },
        "id": "CVE-2026-46532-42f55d5e",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/56053c4d1f37955ccf296cf2f6dfd0f7ebd4fae6",
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c",
            "function": "avrc_pars_vendor_cmd"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "319855188188705565088376373846457537461",
            "length": 5740
        },
        "id": "CVE-2026-46532-4324d31d",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/7c004d3fe3022f5f0db98dd1b2d0648a3a9cfb3f",
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c",
            "function": "avrc_pars_vendor_cmd"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "110575243961270844687733609748495197188",
                "213298316964227416384033695662816973855",
                "83352393688845079800515607894768797048",
                "121136837561811885022676005408687346039",
                "100729357990463197507264760283062936174",
                "86182406820322769031293429920693660169",
                "181082300507149714938431511953806340972",
                "149338875224986988652552088234733661270",
                "73730113740310238290143191400514284806",
                "214898376340637766424891091991452672017",
                "65925941903266928906222675378295987661",
                "309667152013518237382638009340955659356",
                "175882895645515702533320913964805694110",
                "86182406820322769031293429920693660169",
                "181082300507149714938431511953806340972",
                "172583923011606494886830058524157977340"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-46532-45ef1f3f",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/c53d05ae526607ca5eae9ffedaf57775eec33a4f",
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "110575243961270844687733609748495197188",
                "213298316964227416384033695662816973855",
                "83352393688845079800515607894768797048",
                "121136837561811885022676005408687346039",
                "100729357990463197507264760283062936174",
                "86182406820322769031293429920693660169",
                "181082300507149714938431511953806340972",
                "149338875224986988652552088234733661270",
                "73730113740310238290143191400514284806",
                "214898376340637766424891091991452672017",
                "65925941903266928906222675378295987661",
                "309667152013518237382638009340955659356",
                "175882895645515702533320913964805694110",
                "86182406820322769031293429920693660169",
                "181082300507149714938431511953806340972",
                "172583923011606494886830058524157977340"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-46532-53071dc9",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/b0959b5ab1dc60398a916c80f14b1816780c801e",
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "110575243961270844687733609748495197188",
                "213298316964227416384033695662816973855",
                "83352393688845079800515607894768797048",
                "121136837561811885022676005408687346039",
                "100729357990463197507264760283062936174",
                "86182406820322769031293429920693660169",
                "181082300507149714938431511953806340972",
                "149338875224986988652552088234733661270",
                "73730113740310238290143191400514284806",
                "214898376340637766424891091991452672017",
                "65925941903266928906222675378295987661",
                "309667152013518237382638009340955659356",
                "175882895645515702533320913964805694110",
                "86182406820322769031293429920693660169",
                "181082300507149714938431511953806340972",
                "172583923011606494886830058524157977340"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-46532-53ba2ba1",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/60f9362f83a05942069532f357c234cd5e5d4302",
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "110575243961270844687733609748495197188",
                "213298316964227416384033695662816973855",
                "83352393688845079800515607894768797048",
                "121136837561811885022676005408687346039",
                "100729357990463197507264760283062936174",
                "86182406820322769031293429920693660169",
                "181082300507149714938431511953806340972",
                "149338875224986988652552088234733661270",
                "73730113740310238290143191400514284806",
                "214898376340637766424891091991452672017",
                "65925941903266928906222675378295987661",
                "309667152013518237382638009340955659356",
                "175882895645515702533320913964805694110",
                "86182406820322769031293429920693660169",
                "181082300507149714938431511953806340972",
                "172583923011606494886830058524157977340"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-46532-5afbfe24",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/56053c4d1f37955ccf296cf2f6dfd0f7ebd4fae6",
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "319855188188705565088376373846457537461",
            "length": 5740
        },
        "id": "CVE-2026-46532-7acbce90",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/c53d05ae526607ca5eae9ffedaf57775eec33a4f",
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c",
            "function": "avrc_pars_vendor_cmd"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "110575243961270844687733609748495197188",
                "213298316964227416384033695662816973855",
                "83352393688845079800515607894768797048",
                "121136837561811885022676005408687346039",
                "100729357990463197507264760283062936174",
                "86182406820322769031293429920693660169",
                "181082300507149714938431511953806340972",
                "149338875224986988652552088234733661270",
                "73730113740310238290143191400514284806",
                "214898376340637766424891091991452672017",
                "65925941903266928906222675378295987661",
                "309667152013518237382638009340955659356",
                "175882895645515702533320913964805694110",
                "86182406820322769031293429920693660169",
                "181082300507149714938431511953806340972",
                "172583923011606494886830058524157977340"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-46532-f0a44b4e",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/8746e5f7e762ead84d2902edec34d84cdd701b2b",
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "110575243961270844687733609748495197188",
                "213298316964227416384033695662816973855",
                "83352393688845079800515607894768797048",
                "121136837561811885022676005408687346039",
                "100729357990463197507264760283062936174",
                "86182406820322769031293429920693660169",
                "181082300507149714938431511953806340972",
                "149338875224986988652552088234733661270",
                "73730113740310238290143191400514284806",
                "214898376340637766424891091991452672017",
                "65925941903266928906222675378295987661",
                "309667152013518237382638009340955659356",
                "175882895645515702533320913964805694110",
                "86182406820322769031293429920693660169",
                "181082300507149714938431511953806340972",
                "172583923011606494886830058524157977340"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-46532-f816bc44",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/espressif/esp-idf/commit/7c004d3fe3022f5f0db98dd1b2d0648a3a9cfb3f",
        "target": {
            "file": "components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c"
        }
    }
]
vanir_signatures_modified
"2026-08-12T16:09:38Z"