CVE-2025-55098: Potential out-of-bounds read in _ux_host_class_audio_device_type_get()
Published Oct 17, 2025
·Updated
In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in uxhostclassaudiodevicetypeget() when parsing a descriptor of an USB audio device.
Affected Software
2 affected components
Eclipse Foundation USBX<6.4.3
Eclipse Threadx Usbx<6.4.3.202503
Event History
Oct 17, 2025
CVE Published
via MITRE·05:36 AM
Data Sourced
via MITRE·05:36 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55098?
CVE-2025-55098 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2025-55098?
To fix CVE-2025-55098, upgrade to Eclipse Foundation USBX version 6.4.3 or later.
3
What issue does CVE-2025-55098 represent?
CVE-2025-55098 represents a potential out of bounds read issue in the USB support module when handling USB audio device descriptors.
4
In which versions of USBX is CVE-2025-55098 present?
CVE-2025-55098 is present in versions of USBX prior to 6.4.3.
5
Who is affected by CVE-2025-55098?
Any user of Eclipse Foundation USBX versions before 6.4.3 that utilizes audio device support may be affected by CVE-2025-55098.