Skip to main content
Disclosures

STMicroelectronics · STM32Cube USB Host Library / PTP-MTP

USB Host PTP String Length Out-of-Bounds Write

SecMateSECMATE-2026-0030
VendorSTMicroelectronics
ProductSTM32Cube USB Host Library / PTP-MTP
Advisories
Timeline
Reported
Jan 2, 2026
Fixed
Jun 25, 2026
Published
Jul 2, 2026
Summary

STM32Cube USB Host Library 3.5.4 and earlier uses a PTP string length supplied by the USB device without validating it against fixed 255-byte buffers or the received payload. A malicious PTP/MTP device can trigger a one-byte overflow and out-of-bounds payload reads during string parsing, causing memory corruption or a host crash. ST fixed the issue in USB Host Library 3.5.5.

What's hidden in yours?

Find out