Skip to main content
Disclosures

STMicroelectronics · STM32Cube USB Host Library / Audio

USB Host Audio Format Descriptor Invalid Dereference

SecMateSECMATE-2026-0024
VendorSTMicroelectronics
ProductSTM32Cube USB Host Library / Audio
Advisories
Timeline
Reported
Jan 2, 2026
Fixed
Jun 25, 2026
Published
Jul 2, 2026
Summary

STM32Cube USB Host Library 3.5.4 and earlier dereferences Audio Streaming FormatTypeDesc pointers without first validating that a FORMAT_TYPE descriptor was found and lies within the parsed descriptor data. A malformed USB audio device can trigger a null-pointer dereference or out-of-bounds read during playback or frequency selection, causing a host crash. ST fixed the issue in USB Host Library 3.5.5.

What's hidden in yours?

Find out