CVE-2025-55097: Potential out-of-bounds read in _ux_host_class_audio_streaming_sampling_get()
Published Oct 17, 2025
·Updated
In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in uxhostclassaudiostreamingsamplingget() when parsing a descriptor of an USB streaming device.
Affected Software
2 affected components
Eclipse Foundation USBX<6.4.3
Eclipse Threadx Usbx<6.4.3.202503
Event History
Oct 17, 2025
CVE Published
via MITRE·05:35 AM
Data Sourced
via MITRE·05:35 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55097?
CVE-2025-55097 is categorized as a potential out of bounds read vulnerability, posing a moderate risk to affected systems.
2
What software is affected by CVE-2025-55097?
CVE-2025-55097 affects the Eclipse Foundation USBX versions prior to 6.4.3.
3
How does CVE-2025-55097 affect USB streaming devices?
CVE-2025-55097 may lead to improper parsing of USB streaming device descriptors, potentially allowing unintended memory access.
4
How do I fix CVE-2025-55097?
To mitigate CVE-2025-55097, upgrade to Eclipse Foundation USBX version 6.4.3 or later.
5
Are there any workarounds for CVE-2025-55097?
Currently, the only effective workaround for CVE-2025-55097 is to upgrade to the latest version of USBX.