Description
DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
Published: 2026-07-28
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a classic buffer overflow in the MP3Decoder::UnpackSFMPEG1 function of the schreibfaul1 ESP32-audioI2S library. The overflow arises because attacker‑controlled MP3 metadata is not validated, allowing an adversary to craft a malicious file that corrupts memory and can lead to arbitrary code execution and full compromise of the device.

Affected Systems

The affected product is schreibfaul1 ESP32-audioI2S version 3.4.5. No vendor information is provided in the CNA data, so any deployment of this exact library version is at risk.

Risk and Exploitability

The CVSS score of 9.8 categorizes this flaw as Critical, and although the EPSS score is less than 1 % and the issue is not listed in CISA’s KEV catalog, the potential for remote code execution remains high. The likely attack vector is the delivery of a malicious MP3 file to the device’s decoder, which could be performed over any interface where MP3 data is accepted.

Generated by OpenCVE AI on August 1, 2026 at 00:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch or upgrade to a newer release of schreibfaul1 ESP32‑audioI2S that contains the fix for the buffer overflow.
  • If no patch is currently available, segregate the decoder from untrusted data sources or disable MP3 decoding entirely while maintaining device functionality.
  • Implement input validation or bounds checking on MP3 metadata before it is passed to UnpackSFMPEG1 to prevent overflow.
  • Stay informed of vendor updates and verify that the vulnerable function has been removed or hardened in subsequent releases.

Generated by OpenCVE AI on August 1, 2026 at 00:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References

No reference.

History

Sat, 01 Aug 2026 01:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in MP3 Decoder of schreibfaul1 ESP32‑audioI2S Enables Remote Code Execution

Fri, 31 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 31 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Description schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function due to missing input validation on attacker-controlled MP3 metadata. DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
References

Thu, 30 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Schreibfaul1
Schreibfaul1 esp32-audioi2s
Vendors & Products Schreibfaul1
Schreibfaul1 esp32-audioi2s

Tue, 28 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-120
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 28 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Description schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function due to missing input validation on attacker-controlled MP3 metadata.
References

Subscriptions

Schreibfaul1 Esp32-audioi2s
cve-icon MITRE

Status: REJECTED

Assigner: mitre

Published:

Updated: 2026-07-31T14:34:06.835Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-51252

cve-icon Vulnrichment

Updated:

cve-icon NVD

Status : Rejected

Published: 2026-07-28T15:17:16.370

Modified: 2026-07-31T15:16:29.837

Link: CVE-2026-51252

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T00:45:03Z

Weaknesses

No weakness.