Disclosures
STMicroelectronics · STM32Cube USB Host Library / Audio
USB Host Audio Format Descriptor Invalid Dereference
SecMateSECMATE-2026-0024
VendorSTMicroelectronics
ProductSTM32Cube USB Host Library / Audio
Advisories
Timeline
Reported
Jan 2, 2026
Fixed
Jun 25, 2026
Published
Jul 2, 2026
Summary
STM32Cube USB Host Library 3.5.4 and earlier dereferences Audio Streaming FormatTypeDesc pointers without first validating that a FORMAT_TYPE descriptor was found and lies within the parsed descriptor data. A malformed USB audio device can trigger a null-pointer dereference or out-of-bounds read during playback or frequency selection, causing a host crash. ST fixed the issue in USB Host Library 3.5.5.