CVE-2025-55099
17.10.2025, 06:15
In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_alternate_setting_locate() when parsing a descriptor with attacker-controlled frequency fields.Enginsight
| Vendor | Product | Version |
|---|---|---|
| eclipse | threadx_usbx | 𝑥 < 6.4.3.202503 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration