Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 23 Oct 2025 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eclipse threadx Usbx
|
|
| CPEs | cpe:2.3:o:eclipse:threadx_usbx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Eclipse threadx Usbx
|
|
| Metrics |
cvssV3_1
|
Mon, 20 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Eclipse
Eclipse usbx |
|
| Vendors & Products |
Eclipse
Eclipse usbx |
Fri, 17 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Oct 2025 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In USBX before 6.4.3, the USB support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _ux_host_class_audio_alternate_setting_locate() when parsing a descriptor with attacker-controlled frequency fields. | |
| Title | Potential out-of-bounds read in _ux_host_class_audio_alternate_setting_locate() | |
| Weaknesses | CWE-125 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2025-10-17T13:13:12.730Z
Reserved: 2025-08-06T18:56:43.458Z
Link: CVE-2025-55099
Updated: 2025-10-17T13:13:08.075Z
Status : Analyzed
Published: 2025-10-17T06:15:36.100
Modified: 2025-10-23T12:33:01.977
Link: CVE-2025-55099
No data.
OpenCVE Enrichment
Updated: 2025-10-20T13:24:47Z