USBX security advisories

The table below lists published security advisories for USBX, newest first. Click a GHSA ID for full details.

Published GHSA ID CVE ID Summary Severity

2026‑01‑23

GHSA‑qfmp‑wch9‑rpv2

CVE‑2025‑55095

Unbounded recursion in _ux_host_class_storage_media_mount() via extended partition chains

Medium

2025‑10‑17

GHSA‑r6h5‑fmhc‑v3j7

CVE‑2025‑55097

Potential out-of-bounds read in _ux_host_class_audio_streaming_sampling_get()

Low

2025‑10‑17

GHSA‑j253‑w29r‑9m48

CVE‑2025‑55100

Potential out-of-bounds read in _ux_host_class_audio10_sam_parse_func()

Low

2025‑10‑17

GHSA‑93mv‑fcpr‑9488

CVE‑2025‑55099

Potential out-of-bounds read in _ux_host_class_audio_alternate_setting_locate()

Low

2025‑10‑17

GHSA‑8m9v‑jvjp‑gmxq

CVE‑2025‑55096

Inadequate bounds check and potential underflow in _ux_host_class_hid_report_descriptor_get()

Low

2025‑10‑17

GHSA‑4jc2‑x5hv‑46fq

CVE‑2025‑55098

Potential out-of-bounds read in _ux_host_class_audio_device_type_get()

Low

2023‑12‑03

GHSA‑qjw8‑7w86‑44qj

CVE‑2023‑48694

Azure RTOS USBX Remote Code Execution Vulnerability

Medium

2023‑12‑03

GHSA‑p2p9‑wp2q‑wjv4

CVE‑2023‑48697

Azure RTOS USBX Remote Code Execution Vulnerability

Medium

2023‑12‑03

GHSA‑mwj9‑rpph‑v8wc

CVE‑2023‑48695

Azure RTOS USBX Remote Code Execution Vulnerability

High

2023‑12‑03

GHSA‑h733‑98hq‑f884

CVE‑2023‑48696

Azure RTOS USBX Remote Code Execution Vulnerability

Medium

2023‑12‑03

GHSA‑grhp‑f66q‑x857

CVE‑2023‑48698

Azure RTOS USBX Remote Code Execution Vulnerability

Medium

2022‑11‑03

GHSA‑m9p8‑xrp7‑vvqp

CVE‑2022‑39344

DFU UPLOAD buffer overflow revised

High

2022‑10‑12

GHSA‑gg76‑h537‑xq48

CVE‑2022‑39293

Azure RTOS USBX Host PIMA read integer underflow with buffer overflow

High

2022‑10‑10

GHSA‑chpp‑5fv9‑6368

CVE‑2022‑36063

USBX Host CDC ECD integer underflow with buffer overflow

Medium

2022‑05‑23

GHSA‑hh5p‑x584‑j8hv

CVE‑2022‑29246

Potential buffer overflow in function DFU upload

High

2022‑05‑17

GHSA‑2qc5‑385m‑x862

CVE‑2022‑29223

Potential buffer overflow on HUB descriptor

High