Out of Bound Read Vulnerability in Eclipse Foundation ThreadX USB Support Module
CVE-2025-55100

2.4LOW

Key Information:

Status
Vendor
CVE Published:
17 October 2025

What is CVE-2025-55100?

A potential out of bounds read vulnerability exists in the USB support module of the Eclipse Foundation ThreadX, specifically in the function _ux_host_class_audio10_sam_parse_func(). This issue arises when processing a list of sampling frequencies, which could allow for unintended memory access and affect the stability and security of the application. Users are encouraged to upgrade to USBX version 6.4.3 or later to mitigate this risk.

Affected Version(s)

USBX 0 < 6.4.3

References

CVSS V4

Score:
2.4
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-55100 : Out of Bound Read Vulnerability in Eclipse Foundation ThreadX USB Support Module