VYPR
Unrated severityNVD Advisory· Published Oct 17, 2025· Updated Oct 17, 2025

Potential out-of-bounds read in _ux_host_class_audio_alternate_setting_locate()

CVE-2025-55099

Description

In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_alternate_setting_locate() when parsing a descriptor with attacker-controlled frequency fields.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.