AZL-105338

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105338.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105338
Upstream
  • CVE-2026-92382
Published
2026-09-21T18:17:14Z
Modified
2026-10-02T05:34:59Z
Summary
CVE-2026-92382 affecting package usbredir 0.13.0-1
Details

An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer permanently unsubmitted, defeating the bounds check in usbredirhost_iso_packet() and allowing a usbredir peer to write past the end of the packet descriptor array on every subsequent isochronous packet.

References

Affected packages

Azure Linux:3 / usbredir

Package

Name
usbredir
Purl
pkg:rpm/azure-linux/usbredir

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.13.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105338.json"