CVE-2025-68473 - CVE House
Back to Database
Status published Unknown CVE-2025-68473

ESF-IDF Has Out-of-Bounds Read in ESP32 Bluetooth SDP Result Handling

Vulnerability Description

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.1, 5.4.3, 5.3.4, 5.2.6, 5.1.6, and earlier, in the ESP-IDF Bluetooth host stack (BlueDroid), the function bta_dm_sdp_result() used a fixed-size array uuid_list[32][MAX_UUID_SIZE] to store discovered service UUIDs during the SDP (Service Discovery Protocol) process. On modern Bluetooth devices, it is possible for the number of available services to exceed this fixed limit (32). In such cases, if more than 32 services are discovered, subsequent writes to uuid_list could exceed the bounds of the array, resulting in a potential out-of-bounds write condition.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-68473

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

esp-idf
Vulnerable Versions:
>= 5.5-beta1, <= 5.5.1, >= 5.4-beta1, <= 5.4.3, >= 5.3-beta1, <= 5.3.4, >= 5.2-beta1, <= 5.2.6, <= 5.1.6

Timeline

Official Publish: December 26th, 2025
Last Modified: December 29th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)