CVE 9.3 CRITICAL

ESF-IDF: Out-of-Bounds Write in ESP-TEE Secure Service Wrappers_CVE-2026-45328

9.3 / 10
CRITICAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Description

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c that bridge calls from the user application (i.e. the REE) to TEE-protected hardware peripherals (AES, SHA, ECC, HMAC, SPI, MMU, WDT) and to the security feature like attestation, OTA updates, secure storage. This issue has been patched in versions 5.5.5 and 6.0.1.

AI Analysis

Out-of-Bounds Write in ESP-TEE Secure Service Wrappers

Basic Information

ID CVE-2026-45328
Source GitHub_M
Published Jun 10, 2026 at 00:33

Affected Product

Vendor espressif
Product esp-idf
Version = 5.5.4
Affected Versions espressif esp-idf = 5.5.4
espressif esp-idf = 6.0

CWE Classification

AI Assessment

AI Score 9.3 / 10
AI Severity Critical
Vendor Espressif
Product ESF-IDF
Version 5.5.4, 6.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.