CVE-2025-68657

Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, calls to hid_host_device_close() can free the same usb_transfer_t twice. The USB event callback and user code share the hid_iface_t state without locking, so both can tear down a READY interface simultaneously, corrupting heap metadata inside the ESP USB host stack. This vulnerability is fixed in 1.1.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:espressif:usb_host_hid_driver:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:59

Type Values Removed Values Added
Summary
  • (es) El controlador Espressif ESP-IDF USB Host HID (dispositivo de interfaz humana) permite el acceso a dispositivos HID. Antes de la versión 1.1.0, las llamadas a hid_host_device_close() pueden liberar la misma usb_transfer_t dos veces. La devolución de llamada de eventos USB y el código de usuario comparten el estado de hid_iface_t sin bloqueo, por lo que ambos pueden desmantelar una interfaz READY simultáneamente, corrompiendo los metadatos del heap dentro de la pila de host USB de ESP. Esta vulnerabilidad se corrige en la versión 1.1.0.
References () https://github.com/espressif/esp-usb/security/advisories/GHSA-gp8r-qjfr-gqfv - Vendor Advisory, Patch () https://github.com/espressif/esp-usb/security/advisories/GHSA-gp8r-qjfr-gqfv - Patch, Vendor Advisory

22 Jan 2026, 15:47

Type Values Removed Values Added
First Time Espressif
Espressif usb Host Hid Driver
CPE cpe:2.3:a:espressif:usb_host_hid_driver:*:*:*:*:*:*:*:*
References () https://components.espressif.com/components/espressif/usb_host_hid/versions/1.1.0/changelog - () https://components.espressif.com/components/espressif/usb_host_hid/versions/1.1.0/changelog - Release Notes
References () https://github.com/espressif/esp-usb/commit/cd28106e9f72ac2719682c06f94601f9f034390b - () https://github.com/espressif/esp-usb/commit/cd28106e9f72ac2719682c06f94601f9f034390b - Patch
References () https://github.com/espressif/esp-usb/security/advisories/GHSA-gp8r-qjfr-gqfv - () https://github.com/espressif/esp-usb/security/advisories/GHSA-gp8r-qjfr-gqfv - Vendor Advisory, Patch

12 Jan 2026, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-12 18:15

Updated : 2026-06-17 09:59


NVD link : CVE-2025-68657

Mitre link : CVE-2025-68657

CVE.ORG link : CVE-2025-68657


JSON object : View

Products Affected

espressif

  • usb_host_hid_driver
CWE
CWE-415

Double Free

CWE-667

Improper Locking