Description
An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer permanently unsubmitted, defeating the bounds check in usbredirhost_iso_packet() and allowing a usbredir peer to write past the end of the packet descriptor array on every subsequent isochronous packet.
Published: 2026-09-21
Score: 4.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Heap memory corruption
Action: Patch or Remove
AI Analysis

Impact

An out-of-bounds write flaw exists in the usbredir user-space component, where starting an isochronous OUT stream with a transfer count of one bypasses a bounds check in usbredirhost_iso_packet(). The flaw allows a usbredir peer to write beyond the end of the packet descriptor array on each subsequent isochronous packet, corrupting heap memory. This type of memory corruption can lead to unpredictable behavior, including potential privilege escalation or denial of service, depending on how the corrupted memory is exploited.

Affected Systems

Red Hat Enterprise Linux 10, 6, 7, 8, and 9 include the affected usbredir package. Systems running these releases should verify which usbredir version they are using, as the vulnerability is present across all mentioned RHEL versions.

Risk and Exploitability

The CVSS score of 4.1 indicates moderate severity, while the EPSS score is currently unavailable and the vulnerability is not listed in CISA KEV. The likely attack vector is a local or remote usbredir peer that can initiate or inject isochronous packets; full exploitation requires the attacker to have access to a usbredir session, but once achieved the vulnerability could be leveraged to corrupt heap memory.

Generated by OpenCVE AI on September 21, 2026 at 18:36 UTC.

Remediation

Vendor Workaround

If USB redirection is not a required feature, consider removing the `usbredir` package. This action will eliminate the attack surface but may affect functionality that relies on USB device redirection, particularly in virtualized environments.


OpenCVE Recommended Actions

  • Update the usbredir package to a patched version released by Red Hat.
  • If USB redirection is unnecessary, uninstall or remove the usbredir package to eliminate the attack surface.
  • Disable USB device redirection in virtual machine configuration or hypervisor settings to prevent usbredir peers from connecting.

Generated by OpenCVE AI on September 21, 2026 at 18:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Title usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write Usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References

Fri, 18 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Description An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer permanently unsubmitted, defeating the bounds check in usbredirhost_iso_packet() and allowing a usbredir peer to write past the end of the packet descriptor array on every subsequent isochronous packet.
Title usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write
Weaknesses CWE-787
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H'}

threat_severity

Moderate


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-21T20:45:08.748Z

Reserved: 2026-09-16T08:00:35.754Z

Link: CVE-2026-92382

cve-icon Vulnrichment

Updated: 2026-09-21T19:40:38.780Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-21T18:17:14.593

Modified: 2026-09-22T19:37:36.747

Link: CVE-2026-92382

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-17T12:20:57Z

Links: CVE-2026-92382 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T18:45:18Z

Weaknesses