Disclosures
STMicroelectronics · STM32Cube USB Device Library / MSC
USB Device MSC READ CAPACITY(16) Buffer Overflow
SecMateSECMATE-2026-0021
VendorSTMicroelectronics
ProductSTM32Cube USB Device Library / MSC
Advisories
Timeline
Reported
Jan 2, 2026
Fixed
Apr 8, 2026
Published
Apr 23, 2026
Summary
STM32Cube USB Device Library 2.11.5 and earlier uses the host-controlled Allocation Length from a READ CAPACITY(16) command without bounding it to the fixed MSC data buffer. A malicious USB host can trigger an out-of-bounds write while the buffer is cleared and an out-of-bounds read when the response is transmitted, causing memory corruption, data exposure, or a device crash. ST fixed the issue in USB Device Library 2.11.6.