Skip to main content
Disclosures

Espressif · esp-usb / usb_host_uvc

Stack Buffer Overflow in UVC Descriptor Printing

6.8medium
SecMateSECMATE-2025-0034
VendorEspressif
Productesp-usb / usb_host_uvc
VectorCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
Published
Jan 11, 2026
Summary

Espressif's esp-usb UVC host component before version 2.4.0 contains a stack buffer overflow in configuration descriptor parsing when verbose descriptor printing is enabled. A malicious USB Video Class device can provide an oversized descriptor that corrupts stack memory, causing denial of service and potentially altering control flow.

Read the technical analysis

What's hidden in yours?

Find out