Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 22 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Espressif usb Host Uvc Class Driver
|
|
| CPEs | cpe:2.3:a:espressif:usb_host_uvc_class_driver:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Espressif usb Host Uvc Class Driver
|
Tue, 13 Jan 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Espressif
Espressif esp-usb |
|
| Vendors & Products |
Espressif
Espressif esp-usb |
Mon, 12 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 12 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Espressif ESP-IDF USB Host UVC Class Driver allows video streaming from USB cameras. Prior to 2.4.0, a vulnerability in the esp-usb UVC host implementation allows a malicious USB Video Class (UVC) device to trigger a stack buffer overflow during configuration-descriptor parsing. When UVC configuration-descriptor printing is enabled, the host prints detailed descriptor information provided by the connected USB device. A specially crafted UVC descriptor may advertise an excessively large length. Because this value is not validated before being copied into a fixed-size stack buffer, an attacker can overflow the buffer and corrupt memory. This vulnerability is fixed in 2.4.0. | |
| Title | Espressif ESP-IDF USB Host UVC Class Driver has a stack buffer overflow in UVC descriptor printing | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-12T18:37:35.287Z
Reserved: 2025-12-19T18:50:09.991Z
Link: CVE-2025-68622
Updated: 2026-01-12T18:37:30.893Z
Status : Analyzed
Published: 2026-01-12T17:15:53.050
Modified: 2026-01-22T15:50:31.880
Link: CVE-2025-68622
No data.
OpenCVE Enrichment
Updated: 2026-01-13T09:27:29Z