Buffer Overflow Vulnerability in Espressif ESP-IDF USB Host UVC Driver
CVE-2025-68622

6.8MEDIUM

Key Information:

Vendor

Espressif

Status
Vendor
CVE Published:
12 January 2026

What is CVE-2025-68622?

The Espressif ESP-IDF USB Host UVC Class Driver exhibits a vulnerability that allows a malicious USB Video Class (UVC) device to exploit a stack buffer overflow during the parsing of configuration descriptors. When UVC configuration descriptor printing is enabled, the driver processes detailed information from the connected USB device. If a specially crafted UVC descriptor specifies an excessively large length, the lack of validation allows an attacker to overflow the fixed-size stack buffer, leading to potential memory corruption. This vulnerability has been addressed in version 2.4.0, and users are encouraged to upgrade to this version to mitigate the risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

esp-usb < 2.4.0

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.