CVE-2026-25532 | Espressif ESP-IDF 5.1.6/5.2.6/5.3.4/5.4.3/5.5.2 wpabuf_put_data frag_len integer underflow (GHSA-m2h2-683f-9mw7)
A vulnerability classified as problematic was found in Espressif ESP-IDF 5.1.6/5.2.6/5.3.4/5.4.3/5.5.2. This impacts the function wpabuf_put_data. Executing a manipulation of the argument frag_len can lead to integer underflow.
This vulnerability is handled as CVE-2026-25532. The attack can only be done within the local network. There is not any exploit available.
Upgrading the affected component is advised.