Back to overview

CVE-2026-51254

HIGH Exploitation: PoC
7.8
CVSS 3.1
Description
schreibfaul1 ESP32-audioI2S v3.4.5 has an integer underflow vulnerability in the MP3Decoder::GetBits() function of the MP3 decoder due to unchecked bit reading operations. The lack of validation on the nBits parameter causes the cachedBits counter to underflow to negative values, leading to invalid bit manipulation, incorrect bitstream parsing, application crash, or arbitrary code execution via a specially crafted MP3 file.

Metadata

CVE ID
CVE-2026-51254
State
PUBLISHED
Assigner
mitre
Reserved
2026-06-07 00:00 UTC
Published
2026-07-28 00:00 UTC
Last updated
2026-07-28 18:30 UTC
Primary CWE
CWE-191
CWE-191 Integer Underflow (Wrap or Wraparound)
Vendor / Product
n/a / n/a
Sources
cve.org  ·  NVD

Severity & Metrics

7.8 HIGH CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
n/a n/a n/a
Weakness (CWE)
CWESourceDescription
cna n/a
CWE-191 adp CWE-191 Integer Underflow (Wrap or Wraparound)
CVSS scores (1)
ScoreSeverityVersionSourceVector
7.8 HIGH 3.1 adp CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Back to overview