Disclosures
STMicroelectronics · STM32Cube USB Device Library / Core
USB Device GET_STATUS Endpoint Address Out-of-Bounds Write
SecMateSECMATE-2026-0020
VendorSTMicroelectronics
ProductSTM32Cube USB Device Library / Core
Advisories
Timeline
Reported
Jan 2, 2026
Fixed
Apr 8, 2026
Published
Apr 23, 2026
Summary
STM32Cube USB Device Library 2.11.5 and earlier validates only the low endpoint-number bits of a GET_STATUS request before using a wider attacker-controlled endpoint address to index fixed endpoint arrays. A malicious USB host can set additional address bits and cause an out-of-bounds status write, resulting in memory corruption or a device crash. ST fixed the issue in USB Device Library 2.11.6.