CVE-2025-68656

MEDIUM

Espressif USB Host HID Driver < 1.1.0 - Use-After-Free via Oversized Report Descriptor

Title source: llm
STIX 2.1

Description

Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, usb_class_request_get_descriptor() frees and reallocates hid_device->ctrl_xfer when an oversized descriptor is requested but continues to use the stale local pointer, leading to an immediate use-after-free when processing attacker-controlled Report Descriptor lengths. This vulnerability is fixed in 1.1.0.

Scores

CVSS v3 6.8
EPSS 0.0018
EPSS Percentile 8.0%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-416
Status published
Products (1)
espressif/usb_host_hid_driver < 1.1.0
Published Jan 12, 2026
Tracked Since Feb 18, 2026