Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 22 Jan 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Espressif usb Host Hid Driver
|
|
| CPEs | cpe:2.3:a:espressif:usb_host_hid_driver:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Espressif usb Host Hid Driver
|
Tue, 13 Jan 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Espressif
Espressif esp-usb |
|
| Vendors & Products |
Espressif
Espressif esp-usb |
Mon, 12 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 12 Jan 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, usb_class_request_get_descriptor() frees and reallocates hid_device->ctrl_xfer when an oversized descriptor is requested but continues to use the stale local pointer, leading to an immediate use-after-free when processing attacker-controlled Report Descriptor lengths. This vulnerability is fixed in 1.1.0. | |
| Title | Espressif ESP-IDF USB Host HID (Human Interface Device) Driver Descriptor Use-After-Free Vulnerability | |
| Weaknesses | CWE-416 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-12T18:39:37.514Z
Reserved: 2025-12-22T17:55:15.945Z
Link: CVE-2025-68656
Updated: 2026-01-12T18:39:33.263Z
Status : Analyzed
Published: 2026-01-12T18:15:48.467
Modified: 2026-01-22T15:47:56.317
Link: CVE-2025-68656
No data.
OpenCVE Enrichment
Updated: 2026-01-13T09:27:28Z