Impact
An out-of-bounds write flaw exists in the usbredir user-space component, where starting an isochronous OUT stream with a transfer count of one bypasses a bounds check in usbredirhost_iso_packet(). The flaw allows a usbredir peer to write beyond the end of the packet descriptor array on each subsequent isochronous packet, corrupting heap memory. This type of memory corruption can lead to unpredictable behavior, including potential privilege escalation or denial of service, depending on how the corrupted memory is exploited.
Affected Systems
Red Hat Enterprise Linux 10, 6, 7, 8, and 9 include the affected usbredir package. Systems running these releases should verify which usbredir version they are using, as the vulnerability is present across all mentioned RHEL versions.
Risk and Exploitability
The CVSS score of 4.1 indicates moderate severity, while the EPSS score is currently unavailable and the vulnerability is not listed in CISA KEV. The likely attack vector is a local or remote usbredir peer that can initiate or inject isochronous packets; full exploitation requires the attacker to have access to a usbredir session, but once achieved the vulnerability could be leveraged to corrupt heap memory.
OpenCVE Enrichment