CVE-2025-55096: Inadequate bounds check and potential underflow in _ux_host_class_hid_report_descriptor_get()
Published Oct 17, 2025
·Updated
In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in uxhostclasshidreportdescriptorget() when parsing a descriptor of an USB HID device.
Affected Software
2 affected components
Eclipse Foundation USBX<6.4.3
Eclipse Threadx Usbx<6.4.3.202503
Event History
Oct 17, 2025
CVE Published
via MITRE·05:32 AM
Data Sourced
via MITRE·05:32 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55096?
CVE-2025-55096 has a medium severity due to the potential out of bound read issue that could be exploited.
2
How do I fix CVE-2025-55096?
To fix CVE-2025-55096, upgrade to USBX version 6.4.3 or later as this vulnerability has been addressed in that release.
3
Who is affected by CVE-2025-55096?
CVE-2025-55096 affects all users of Eclipse Foundation USBX versions prior to 6.4.3.
4
What kind of issue is presented in CVE-2025-55096?
CVE-2025-55096 presents an out of bounds read vulnerability when parsing USB HID device descriptors.
5
Is CVE-2025-55096 specific to certain devices?
CVE-2025-55096 specifically affects USB HID devices when used with affected versions of the USBX support module.