CVE-2026-92382Medium· 4.1▾ SunlitAn out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer permanently unsubmitted, defeating the bounds check in usbredirhost_iso_packet() …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 22.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer permanently unsubmitted, defeating the bounds check in usbredirhost_iso_packet() and allowing a usbredir peer to write past the end of the packet descriptor array on every subsequent isochronous packet.
usbredir (all versions)usbredirusbredir (all versions)usbredir (all versions)usbredir (all versions)Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
If USB redirection is not a required feature, consider removing the usbredir package. This action will eliminate the attack surface but may affect functionality that relies on USB device redirection, particularly in virtualized environments.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-91142Low· 3.6A flaw was found in Cockpit
CVE-2026-81627High· 8.2A flaw was found in QEMU
CVE-2026-90947High· 7.8A flaw was found in GIMP
CVE-2026-90949High· 7.8A flaw was found in GIMP's PSP (Paint Shop Pro) file loader
CVE-2026-90948High· 7.8A flaw was found in GIMP's ICO file loader
CVE-2026-94449High· 7.5A flaw was found in the SmallRye Fault Tolerance library, which is used by Quarkus to provide strategies like retries and circuit breakers for microservices