ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, a use-after-free vulnerability was reported in the BLE provisioning transport (protocomm_ble) layer. The issue can be triggered by a remote BLE client while the device is in provisioning mode. The vulnerability occurred when provisioning was stopped with keep_ble_on = true. In this configuration, internal protocomm_ble state and GATT metadata were freed while the BLE stack and GATT services remained active. Subsequent BLE read or write callbacks dereferenced freed memory, allowing a connected or newly connected client to trigger invalid memory acces. This issue has been patched in versions 5.5.3, 5.4.4, 5.3.5, 5.2.7, and 5.1.7.
Metrics
Affected Vendors & Products
References
History
Fri, 20 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:espressif:esp-idf:5.1.6:*:*:*:*:*:*:* cpe:2.3:a:espressif:esp-idf:5.2.6:*:*:*:*:*:*:* cpe:2.3:a:espressif:esp-idf:5.3.4:*:*:*:*:*:*:* cpe:2.3:a:espressif:esp-idf:5.4.3:*:*:*:*:*:*:* cpe:2.3:a:espressif:esp-idf:5.5.2:*:*:*:*:*:*:* |
Thu, 05 Feb 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Espressif
Espressif esp-idf |
|
| Vendors & Products |
Espressif
Espressif esp-idf |
Wed, 04 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Feb 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.2, 5.4.3, 5.3.4, 5.2.6, and 5.1.6, a use-after-free vulnerability was reported in the BLE provisioning transport (protocomm_ble) layer. The issue can be triggered by a remote BLE client while the device is in provisioning mode. The vulnerability occurred when provisioning was stopped with keep_ble_on = true. In this configuration, internal protocomm_ble state and GATT metadata were freed while the BLE stack and GATT services remained active. Subsequent BLE read or write callbacks dereferenced freed memory, allowing a connected or newly connected client to trigger invalid memory acces. This issue has been patched in versions 5.5.3, 5.4.4, 5.3.5, 5.2.7, and 5.1.7. | |
| Title | ESF-IDF Has Use-after-free Vulnerability in BLE Provisioning | |
| Weaknesses | CWE-416 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-02-04T17:58:18.605Z
Updated: 2026-02-04T19:24:17.464Z
Reserved: 2026-02-02T18:21:42.486Z
Link: CVE-2026-25507
Updated: 2026-02-04T19:24:11.532Z
Status : Analyzed
Published: 2026-02-04T18:16:09.360
Modified: 2026-02-20T17:12:46.537
Link: CVE-2026-25507
No data.