PT-2026-2280 · Espressif · Esp-Idf

CVE-2025-68622

·

Publicado

2026-01-12

·

Atualizado

2026-01-12

CVSS v3.1

6.8

Média

VetorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Espressif ESP-IDF versions prior to 2.4.0
Description The ESP-IDF USB Host UVC Class Driver, used for video streaming from USB cameras, contains a flaw in the esp-usb UVC host implementation. A malicious USB Video Class (UVC) device can trigger a stack buffer overflow during configuration-descriptor parsing. When UVC configuration-descriptor printing is enabled, the host prints descriptor information from the USB device. A crafted UVC descriptor advertising a large length, which is not validated before being copied into a fixed-size stack buffer, can cause a buffer overflow and memory corruption.
Recommendations Update to version 2.4.0 or later.

Exploit

Correção

Stack Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-68622
GHSA-G65H-9GGQ-9827

Produtos afetados

Esp-Idf