Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-68657— espressif/usb_host_hid Double-Free Race Condition in USB Host HID Device Close Path

CVSS 6.4 · Medium EPSS 0.02% · P5
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-68657

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
espressif/usb_host_hid Double-Free Race Condition in USB Host HID Device Close Path
Source: NVD (National Vulnerability Database)
Vulnerability Description
Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, calls to hid_host_device_close() can free the same usb_transfer_t twice. The USB event callback and user code share the hid_iface_t state without locking, so both can tear down a READY interface simultaneously, corrupting heap metadata inside the ESP USB host stack. This vulnerability is fixed in 1.1.0.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
双重释放
Source: NVD (National Vulnerability Database)
Vulnerability Title
Espressif ESP-IDF 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Espressif ESP-IDF是中国乐鑫(Espressif)公司的一款物联网开发框架。 Espressif ESP-IDF 1.1.0之前版本存在安全漏洞,该漏洞源于USB事件回调和用户代码共享状态而无锁定,可能导致双重释放。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
espressifesp-usb < 1.1.0 -

II. Public POCs for CVE-2025-68657

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-68657

登录查看更多情报信息。

Same Patch Batch · espressif · 2026-01-12 · 3 CVEs total

CVE-2025-686226.8 MEDIUMEspressif ESP-IDF USB Host UVC Class Driver has a stack buffer overflow in UVC descriptor
CVE-2025-686566.8 MEDIUMEspressif ESP-IDF USB Host HID (Human Interface Device) Driver Descriptor Use-After-Free V

IV. Related Vulnerabilities

V. Comments for CVE-2025-68657

No comments yet


Leave a comment