CVE-2025-55099: Potential out-of-bounds read in _ux_host_class_audio_alternate_setting_locate()
Published Oct 17, 2025
·Updated
In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in uxhostclassaudioalternatesettinglocate() when parsing a descriptor with attacker-controlled frequency fields.
Affected Software
2 affected components
Eclipse Foundation USBX<6.4.3
Eclipse Threadx Usbx<6.4.3.202503
Event History
Oct 17, 2025
CVE Published
via MITRE·05:38 AM
Data Sourced
via MITRE·05:38 AM
DescriptionWeakness
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55099?
CVE-2025-55099 is classified as a medium severity vulnerability due to the potential out of bounds read issue.
2
How do I fix CVE-2025-55099?
To fix CVE-2025-55099, upgrade to USBX version 6.4.3 or later.
3
What software is affected by CVE-2025-55099?
CVE-2025-55099 affects Eclipse Foundation USBX versions prior to 6.4.3.
4
What type of vulnerability is CVE-2025-55099?
CVE-2025-55099 is an out of bounds read vulnerability in the USB support module.
5
What is the potential impact of CVE-2025-55099?
The potential impact of CVE-2025-55099 includes unauthorized access and information disclosure due to attacker-controlled input.