{"id":"CVE-2026-92382","title":"Usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write","summary":"An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer permanently unsubmitted, defeating the bounds check in usbredirhost_iso_packet() …","severity":"medium","cvss":4.1,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H","cvssSource":"cna","cwe":["CWE-787"],"vendor":"Red Hat","product":"usbredir","affected":["usbredir (all versions)","usbredir","usbredir (all versions)","usbredir (all versions)","usbredir (all versions)"],"published":"2026-09-21","updated":"2026-09-21","sourceUpdated":"2026-09-21T17:28:21.411Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-92382","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-92382"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2535972","label":"RHBZ#2535972"}],"tags":["cve.org"],"ingestedAt":"2026-09-21T17:49:53.180Z","slug":"CVE-2026-92382","body":"## Overview\n\nAn out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer permanently unsubmitted, defeating the bounds check in usbredirhost_iso_packet() and allowing a usbredir peer to write past the end of the packet descriptor array on every subsequent isochronous packet.\n\n## Affected\n\n- `usbredir (all versions)`\n- `usbredir`\n- `usbredir (all versions)`\n- `usbredir (all versions)`\n- `usbredir (all versions)`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n### Workarounds\n\nIf USB redirection is not a required feature, consider removing the `usbredir` package. This action will eliminate the attack surface but may affect functionality that relies on USB device redirection, particularly in virtualized environments.","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":22.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}