Out-of-Bounds Write Vulnerability in usbredir Affects Multiple Platforms
CVE-2026-92382
4.1MEDIUM
What is CVE-2026-92382?
A critical flaw has been identified in usbredir, specifically an out-of-bounds write issue. This vulnerability occurs when initiating an isochronous OUT stream with a transfer count of one. The stream's single transfer buffer is left permanently unsubmitted, which bypasses the crucial bounds check in usbredirhost_iso_packet(). Consequently, this allows a usbredir peer to overwrite data beyond the packet descriptor array on every isochronous packet, potentially leading to data corruption and instability in affected systems.
References
CVSS V3.1
Score:
4.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank Calif.io for reporting this issue.