Stack-based buffer overflow in ESP-IDF - CVE-2026-55687
Published: June 24, 2026
ESP-IDF
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to stack-based buffer overflow in the JPEG decoder header parser when parsing a crafted DQT marker in a JPEG file. A remote attacker can supply a specially crafted JPEG image to cause a denial of service.
Code execution may be possible on builds without strong stack protection, but this has not been demonstrated.