Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
If USB redirection is not a required feature, consider removing the `usbredir` package. This action will eliminate the attack surface but may affect functionality that relies on USB device redirection, particularly in virtualized environments.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 21 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 21 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write | Usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| CPEs | cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
|
Fri, 18 Sep 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer permanently unsubmitted, defeating the bounds check in usbredirhost_iso_packet() and allowing a usbredir peer to write past the end of the packet descriptor array on every subsequent isochronous packet. | |
| Title | usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-21T20:45:08.748Z
Reserved: 2026-09-16T08:00:35.754Z
Link: CVE-2026-92382
Updated: 2026-09-21T19:40:38.780Z
Status : Received
Published: 2026-09-21T18:17:14.593
Modified: 2026-09-21T21:17:16.360
Link: CVE-2026-92382
OpenCVE Enrichment
Updated: 2026-09-21T18:45:18Z
-
CWE-787
Out-of-bounds Write