CVE-2026-25508 | Espressif ESP-IDF 5.1.6/5.2.6/5.3.4/5.4.3/5.5.2 BLE Provisioning Transport protocomm_ble out-of-bounds (GHSA-9j5x-rf36-54x9)
A vulnerability classified as critical has been found in Espressif ESP-IDF 5.1.6/5.2.6/5.3.4/5.4.3/5.5.2. This affects the function protocomm_ble of the component BLE Provisioning Transport. Performing a manipulation results in out-of-bounds read.
This vulnerability is known as CVE-2026-25508. Access to the local network is required for this attack. No exploit is available.
It is recommended to upgrade the affected component.