CVE-2026-17054
Last modified
CVE-2026-17054 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-processor in esp_hosted_event_task(). For control frames it took the 16-bit TLV field data_length straight off the wire and passed it to pb_istream_from_buffer(frame.data_value, frame.data_length) without checking it against the frame length or the receive buffer. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-processor in esp_hosted_event_task(). For control frames it took the 16-bit TLV field data_length straight off the wire and passed it to pb_istream_from_buffer(frame.data_value, frame.data_length) without checking it against the frame length or the receive buffer. frame.data_value sits 26 bytes into a 3188-byte stack object, so a data_length of up to 0xFFFF makes pb_decode() read up to roughly 62 KB past the end of that object. Only the first fragment of a fragmented control response carries a TLV header; the pre-fix driver performed half-duplex SPI transactions and silently discarded any frame the co-processor queued while the host was transmitting (esp_hosted_hal_spi_transfer() aliased the RX buffer onto the TX buffer). When the discarded frame is the first fragment of a fragmented response, the driver treats the next fragment as a new frame — its per-fragment header and checksum are genuine, so both validation steps pass — and reads the TLV header out of raw protobuf continuation bytes. Those bytes come from control responses whose size and content an adjacent, unauthenticated attacker can influence, notably the AP scan list, which grows with the number and SSID length of access points in radio range. The impact is denial of service rather than disclosure. Reading past the end of the RAM region faults the device, and CONFIG_NANOPB_ENABLE_MALLOC is selected by the driver, so garbage length prefixes read out of bounds also drive heap allocations. The out-of-bounds bytes themselves do not reach the application: pb_decode() is started mid-stream on raw protobuf continuation bytes and so almost always fails outright, and anything that did decode would still have to pass esp_hosted_response(), which requires an exact msg_id match against the pending request, and then esp_hosted_ctrl_response(), which requires a success resp — an attacker influences the size and content of legitimate control responses, not the structure decoded out of misaligned bytes. Two related defects in the same receive path make the denial of service permanent: the fragment reassembly guard was sized with ESP_FRAME_SIZE instead of ESP_FRAME_MAX_PAYLOAD and, when tripped, returned from the sole RX thread instead of dropping the frame, and unhandled control events were queued with k_msgq_put(..., K_FOREVER) on an eight-entry queue that nothing drains, blocking that same thread. The driver has no watchdog or restart path, so either condition ends all Wi-Fi reception until the device is rebooted.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| zephyrproject | zephyr | >= 4.2.0, < 4.4.2 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-17054?
How severe is CVE-2026-17054?
How do I fix CVE-2026-17054?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-17047IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote …5.4
- CVE-2026-17048A flaw was found in the Keycloak Admin REST API, which is us…4.9
- CVE-2026-1705A vulnerability was detected in D-Link DSL-6641K N8.TR069.20…2.4
- CVE-2026-17050The experimental USB host stack allocates a per-device confi…5.7
- CVE-2026-17051The Intel SEDI IPM (inter-processor mailbox) driver in drive…6
- CVE-2026-17052The Time-aware GPIO syscall verification handler z_vrfy_tgpi…7.8
- CVE-2026-17057IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker t…9.1
- CVE-2026-17059A flaw was found in the role-users endpoint of the keycloak-…6.5
- CVE-2026-1706The All-in-One Video Gallery plugin for WordPress is vulnera…6.1
- CVE-2026-17060IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a …9.1
- CVE-2026-17061A Deserialization of Untrusted Data vulnerability affecting …10
- CVE-2026-17063IBM Power Systems Firmware FW1120.00, FW1110.00 through FW11…7.9
Are you affected by CVE-2026-17054?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
