Impact
A null pointer dereference occurs when the i2s_esp32_trigger_check() function accepts an unsupported direction and accesses a missing stream structure without verifying the pointer. The resulting read at address 0 causes a kernel exception that halts the system, delivering a complete system‑wide denial of service. The vulnerability does not lead to privilege escalation or information disclosure; it merely destabilizes the host.
Affected Systems
The flaw is present in the Zephyr RTOS I2S driver for Espressif ESP32 series chips, including ESP32, ESP32-C5, and ESP32-C6. It affects builds that enable userspace (CONFIG_USERSPACE) and the associated RISC‑V PMP configuration enabled on ESP32‑C6 HPCORE and ESP32‑C5 when it is not built for MCUboot. The relevant Zephyr releases that contain the bug are v4.2.0 and later, up to the version that incorporated the hardening patch (v4.4.0).
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity issue. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers who can obtain an unprivileged user‑mode thread with access to an I2S device can trigger the unsafe direction, provoking a crash. Since the exploit requires only a bad direction argument with no user‑controlled offset, the likelihood is low but non‑negligible in environments where userspace I2S usage is enabled. The vulnerability is limited to availability and does not permit code execution or data exfiltration.
OpenCVE Enrichment