I2S Driver Vulnerability in Espressif Devices
CVE-2026-19737

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
11 October 2026

What is CVE-2026-19737?

A vulnerability exists in the I2S driver of Espressif devices due to an improper input validation check in the i2s_esp32_trigger_check() function. This flaw allows unprivileged user-mode threads in a userspace environment to trigger a system-wide denial of service by instigating a read from a null pointer, which results in a fatal error, halting the system. The driver fails to validate the direction argument properly, which could lead to dereferencing a NULL pointer if the specified stream direction is not correctly set up. Although the potential danger is limited due to the absence of an attacker-controlled offset, the risk of a service interruption underscores the necessity for prompt remedial action. Fixes have been introduced in later versions to ensure requests for non-existent stream directions return an appropriate error response instead of leading to a crash.

Affected Version(s)

zephyr 4.4.0 < 4.5.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.