Buffer Overflow Vulnerability in Espressif ESP-IDF USB Host UVC Driver
CVE-2025-68622
What is CVE-2025-68622?
The Espressif ESP-IDF USB Host UVC Class Driver exhibits a vulnerability that allows a malicious USB Video Class (UVC) device to exploit a stack buffer overflow during the parsing of configuration descriptors. When UVC configuration descriptor printing is enabled, the driver processes detailed information from the connected USB device. If a specially crafted UVC descriptor specifies an excessively large length, the lack of validation allows an attacker to overflow the fixed-size stack buffer, leading to potential memory corruption. This vulnerability has been addressed in version 2.4.0, and users are encouraged to upgrade to this version to mitigate the risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
esp-usb < 2.4.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
