Skip to main content
Disclosures

STMicroelectronics · STM32Cube USB Device Library / Core

USB Device GET_STATUS Endpoint Address Out-of-Bounds Write

SecMateSECMATE-2026-0020
VendorSTMicroelectronics
ProductSTM32Cube USB Device Library / Core
Advisories
Timeline
Reported
Jan 2, 2026
Fixed
Apr 8, 2026
Published
Apr 23, 2026
Summary

STM32Cube USB Device Library 2.11.5 and earlier validates only the low endpoint-number bits of a GET_STATUS request before using a wider attacker-controlled endpoint address to index fixed endpoint arrays. A malicious USB host can set additional address bits and cause an out-of-bounds status write, resulting in memory corruption or a device crash. ST fixed the issue in USB Device Library 2.11.6.

What's hidden in yours?

Find out