{"id":"CVE-2026-46532","summary":"ESF-IDF: Heap Out-of-Bounds Read in Bluedroid AVRCP Target Parser","details":"ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0, an out-of-bounds read exists in the BlueDroid AVRCP vendor-command parser (avrc_pars_vendor_cmd() in components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c). This issue has been patched in versions 5.2.7, 5.3.6, 5.4.5, 5.5.4, and 6.0.1.","aliases":["GHSA-3pp8-42fh-3j3c"],"modified":"2026-08-12T16:09:38.880226Z","published":"2026-06-10T00:35:30.465Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46532.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46532.json"},{"type":"ADVISORY","url":"https://github.com/espressif/esp-idf/security/advisories/GHSA-3pp8-42fh-3j3c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46532"},{"type":"FIX","url":"https://github.com/espressif/esp-idf/commit/56053c4d1f37955ccf296cf2f6dfd0f7ebd4fae6"},{"type":"FIX","url":"https://github.com/espressif/esp-idf/commit/60f9362f83a05942069532f357c234cd5e5d4302"},{"type":"FIX","url":"https://github.com/espressif/esp-idf/commit/7c004d3fe3022f5f0db98dd1b2d0648a3a9cfb3f"},{"type":"FIX","url":"https://github.com/espressif/esp-idf/commit/8746e5f7e762ead84d2902edec34d84cdd701b2b"},{"type":"FIX","url":"https://github.com/espressif/esp-idf/commit/b0959b5ab1dc60398a916c80f14b1816780c801e"},{"type":"FIX","url":"https://github.com/espressif/esp-idf/commit/c53d05ae526607ca5eae9ffedaf57775eec33a4f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/espressif/esp-idf","events":[{"introduced":"9ef24e3e2a2c96e720d83c574a3f8699177573da"},{"fixed":"56053c4d1f37955ccf296cf2f6dfd0f7ebd4fae6"},{"fixed":"60f9362f83a05942069532f357c234cd5e5d4302"},{"fixed":"7c004d3fe3022f5f0db98dd1b2d0648a3a9cfb3f"},{"fixed":"8746e5f7e762ead84d2902edec34d84cdd701b2b"},{"fixed":"b0959b5ab1dc60398a916c80f14b1816780c801e"},{"fixed":"c53d05ae526607ca5eae9ffedaf57775eec33a4f"}],"database_specific":{"extracted_events":[{"introduced":"5.2.6"},{"last_affected":"5.2.6"},{"introduced":"5.3.5"},{"last_affected":"5.3.5"},{"introduced":"5.4.4"},{"last_affected":"5.4.4"},{"introduced":"5.5.3"},{"last_affected":"5.5.3"},{"introduced":"6.0"},{"last_affected":"6.0"}],"source":["CPE_STRING","REFERENCES"],"cpe":["cpe:2.3:a:espressif:esp-idf:5.2.6:*:*:*:*:*:*:*","cpe:2.3:a:espressif:esp-idf:5.3.5:*:*:*:*:*:*:*","cpe:2.3:a:espressif:esp-idf:5.4.4:*:*:*:*:*:*:*","cpe:2.3:a:espressif:esp-idf:5.5.3:*:*:*:*:*:*:*","cpe:2.3:a:espressif:esp-idf:6.0:*:*:*:*:*:*:*"]}}],"versions":["5.2.6","5.3.5","5.4.4","5.5.3","6.0","= 5.2.6","= 5.3.5","= 5.4.4","= 5.5.3","= 6.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-46532.json","vanir_signatures_modified":"2026-08-12T16:09:38Z","vanir_signatures":[{"source":"https://github.com/espressif/esp-idf/commit/b0959b5ab1dc60398a916c80f14b1816780c801e","target":{"file":"components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c","function":"avrc_pars_vendor_cmd"},"deprecated":false,"digest":{"function_hash":"319855188188705565088376373846457537461","length":5740},"id":"CVE-2026-46532-16af42b3","signature_type":"Function","signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/espressif/esp-idf/commit/60f9362f83a05942069532f357c234cd5e5d4302","target":{"file":"components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c","function":"avrc_pars_vendor_cmd"},"deprecated":false,"digest":{"function_hash":"319855188188705565088376373846457537461","length":5740},"id":"CVE-2026-46532-2c9a1259"},{"signature_version":"v1","source":"https://github.com/espressif/esp-idf/commit/8746e5f7e762ead84d2902edec34d84cdd701b2b","target":{"file":"components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c","function":"avrc_pars_vendor_cmd"},"deprecated":false,"digest":{"function_hash":"319855188188705565088376373846457537461","length":5740},"id":"CVE-2026-46532-327c346b","signature_type":"Function"},{"target":{"file":"components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c","function":"avrc_pars_vendor_cmd"},"deprecated":false,"digest":{"function_hash":"319855188188705565088376373846457537461","length":5740},"id":"CVE-2026-46532-42f55d5e","signature_type":"Function","signature_version":"v1","source":"https://github.com/espressif/esp-idf/commit/56053c4d1f37955ccf296cf2f6dfd0f7ebd4fae6"},{"source":"https://github.com/espressif/esp-idf/commit/7c004d3fe3022f5f0db98dd1b2d0648a3a9cfb3f","target":{"file":"components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c","function":"avrc_pars_vendor_cmd"},"deprecated":false,"digest":{"function_hash":"319855188188705565088376373846457537461","length":5740},"id":"CVE-2026-46532-4324d31d","signature_type":"Function","signature_version":"v1"},{"id":"CVE-2026-46532-45ef1f3f","signature_type":"Line","signature_version":"v1","source":"https://github.com/espressif/esp-idf/commit/c53d05ae526607ca5eae9ffedaf57775eec33a4f","target":{"file":"components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c"},"deprecated":false,"digest":{"line_hashes":["110575243961270844687733609748495197188","213298316964227416384033695662816973855","83352393688845079800515607894768797048","121136837561811885022676005408687346039","100729357990463197507264760283062936174","86182406820322769031293429920693660169","181082300507149714938431511953806340972","149338875224986988652552088234733661270","73730113740310238290143191400514284806","214898376340637766424891091991452672017","65925941903266928906222675378295987661","309667152013518237382638009340955659356","175882895645515702533320913964805694110","86182406820322769031293429920693660169","181082300507149714938431511953806340972","172583923011606494886830058524157977340"],"threshold":0.9}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/espressif/esp-idf/commit/b0959b5ab1dc60398a916c80f14b1816780c801e","target":{"file":"components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c"},"deprecated":false,"digest":{"line_hashes":["110575243961270844687733609748495197188","213298316964227416384033695662816973855","83352393688845079800515607894768797048","121136837561811885022676005408687346039","100729357990463197507264760283062936174","86182406820322769031293429920693660169","181082300507149714938431511953806340972","149338875224986988652552088234733661270","73730113740310238290143191400514284806","214898376340637766424891091991452672017","65925941903266928906222675378295987661","309667152013518237382638009340955659356","175882895645515702533320913964805694110","86182406820322769031293429920693660169","181082300507149714938431511953806340972","172583923011606494886830058524157977340"],"threshold":0.9},"id":"CVE-2026-46532-53071dc9"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/espressif/esp-idf/commit/60f9362f83a05942069532f357c234cd5e5d4302","target":{"file":"components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c"},"deprecated":false,"digest":{"line_hashes":["110575243961270844687733609748495197188","213298316964227416384033695662816973855","83352393688845079800515607894768797048","121136837561811885022676005408687346039","100729357990463197507264760283062936174","86182406820322769031293429920693660169","181082300507149714938431511953806340972","149338875224986988652552088234733661270","73730113740310238290143191400514284806","214898376340637766424891091991452672017","65925941903266928906222675378295987661","309667152013518237382638009340955659356","175882895645515702533320913964805694110","86182406820322769031293429920693660169","181082300507149714938431511953806340972","172583923011606494886830058524157977340"],"threshold":0.9},"id":"CVE-2026-46532-53ba2ba1"},{"target":{"file":"components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c"},"deprecated":false,"digest":{"line_hashes":["110575243961270844687733609748495197188","213298316964227416384033695662816973855","83352393688845079800515607894768797048","121136837561811885022676005408687346039","100729357990463197507264760283062936174","86182406820322769031293429920693660169","181082300507149714938431511953806340972","149338875224986988652552088234733661270","73730113740310238290143191400514284806","214898376340637766424891091991452672017","65925941903266928906222675378295987661","309667152013518237382638009340955659356","175882895645515702533320913964805694110","86182406820322769031293429920693660169","181082300507149714938431511953806340972","172583923011606494886830058524157977340"],"threshold":0.9},"id":"CVE-2026-46532-5afbfe24","signature_type":"Line","signature_version":"v1","source":"https://github.com/espressif/esp-idf/commit/56053c4d1f37955ccf296cf2f6dfd0f7ebd4fae6"},{"deprecated":false,"digest":{"length":5740,"function_hash":"319855188188705565088376373846457537461"},"id":"CVE-2026-46532-7acbce90","signature_type":"Function","signature_version":"v1","source":"https://github.com/espressif/esp-idf/commit/c53d05ae526607ca5eae9ffedaf57775eec33a4f","target":{"file":"components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c","function":"avrc_pars_vendor_cmd"}},{"id":"CVE-2026-46532-f0a44b4e","signature_type":"Line","signature_version":"v1","source":"https://github.com/espressif/esp-idf/commit/8746e5f7e762ead84d2902edec34d84cdd701b2b","target":{"file":"components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c"},"deprecated":false,"digest":{"line_hashes":["110575243961270844687733609748495197188","213298316964227416384033695662816973855","83352393688845079800515607894768797048","121136837561811885022676005408687346039","100729357990463197507264760283062936174","86182406820322769031293429920693660169","181082300507149714938431511953806340972","149338875224986988652552088234733661270","73730113740310238290143191400514284806","214898376340637766424891091991452672017","65925941903266928906222675378295987661","309667152013518237382638009340955659356","175882895645515702533320913964805694110","86182406820322769031293429920693660169","181082300507149714938431511953806340972","172583923011606494886830058524157977340"],"threshold":0.9}},{"digest":{"line_hashes":["110575243961270844687733609748495197188","213298316964227416384033695662816973855","83352393688845079800515607894768797048","121136837561811885022676005408687346039","100729357990463197507264760283062936174","86182406820322769031293429920693660169","181082300507149714938431511953806340972","149338875224986988652552088234733661270","73730113740310238290143191400514284806","214898376340637766424891091991452672017","65925941903266928906222675378295987661","309667152013518237382638009340955659356","175882895645515702533320913964805694110","86182406820322769031293429920693660169","181082300507149714938431511953806340972","172583923011606494886830058524157977340"],"threshold":0.9},"id":"CVE-2026-46532-f816bc44","signature_type":"Line","signature_version":"v1","source":"https://github.com/espressif/esp-idf/commit/7c004d3fe3022f5f0db98dd1b2d0648a3a9cfb3f","target":{"file":"components/bt/host/bluedroid/stack/avrc/avrc_pars_tg.c"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L"}]}