漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
espressif/usb_host_hid Double-Free Race Condition in USB Host HID Device Close Path
Vulnerability Description
Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows access to HID devices. Prior to 1.1.0, calls to hid_host_device_close() can free the same usb_transfer_t twice. The USB event callback and user code share the hid_iface_t state without locking, so both can tear down a READY interface simultaneously, corrupting heap metadata inside the ESP USB host stack. This vulnerability is fixed in 1.1.0.
CVSS Information
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
双重释放
Vulnerability Title
Espressif ESP-IDF 安全漏洞
Vulnerability Description
Espressif ESP-IDF是中国乐鑫(Espressif)公司的一款物联网开发框架。 Espressif ESP-IDF 1.1.0之前版本存在安全漏洞,该漏洞源于USB事件回调和用户代码共享状态而无锁定,可能导致双重释放。
CVSS Information
N/A
Vulnerability Type
N/A