Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 24 Nov 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Espressif
Espressif esp-idf Espressif esp32 |
|
| Vendors & Products |
Espressif
Espressif esp-idf Espressif esp32 |
Fri, 21 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 21 Nov 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, and 5.3.4, when the ESP32-P4 uses its hardware JPEG decoder, the software parser lacks necessary validation checks. A specially crafted (malicious) JPEG image could exploit the parsing routine and trigger an out-of-bounds array access. This issue has been fixed in versions 5.5.2, 5.4.4, and 5.3.5. At time of publication versions 5.5.2, 5.4.4, and 5.3.5 have not been released but are fixed respectively in commits 4b8f585, c79cb4d, and 34e2726. | |
| Title | ESP32-P4 JPEG Decoder Header Parsing Vulnerability | |
| Weaknesses | CWE-125 CWE-191 |
|
| References |
|
|
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-21T21:56:26.041Z
Reserved: 2025-11-17T20:55:34.691Z
Link: CVE-2025-65092
Updated: 2025-11-21T21:56:21.099Z
Status : Awaiting Analysis
Published: 2025-11-21T22:16:32.560
Modified: 2025-11-25T22:16:42.557
Link: CVE-2025-65092
No data.
OpenCVE Enrichment
Updated: 2025-11-24T09:08:13Z