when parsing a descriptor of an USB HID device.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 23 Oct 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eclipse threadx Usbx
|
|
| CPEs | cpe:2.3:o:eclipse:threadx_usbx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Eclipse threadx Usbx
|
|
| Metrics |
cvssV3_1
|
Mon, 20 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eclipse
Eclipse threadx Netx Duo |
|
| Vendors & Products |
Eclipse
Eclipse threadx Netx Duo |
Fri, 17 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Oct 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_hid_report_descriptor_get() when parsing a descriptor of an USB HID device. | |
| Title | Inadequate bounds check and potential underflow in _ux_host_class_hid_report_descriptor_get() | |
| Weaknesses | CWE-191 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2025-10-17T13:20:44.212Z
Reserved: 2025-08-06T18:56:43.458Z
Link: CVE-2025-55096
Updated: 2025-10-17T13:17:06.803Z
Status : Analyzed
Published: 2025-10-17T06:15:35.630
Modified: 2025-10-23T12:32:46.373
Link: CVE-2025-55096
No data.
OpenCVE Enrichment
Updated: 2025-10-20T13:24:50Z