
PEACH
Un cadre d’isolation des locataires
CVE-2026-92382 is an out-of-bounds write vulnerability (CWE-787) in usbredir, a library used for redirecting USB devices over a network (commonly in virtualized environments). The flaw occurs when an isochronous OUT stream is started with a transfer count of 1, leaving the stream's single transfer buffer permanently unsubmitted and defeating the bounds check in usbredirhost_iso_packet(), allowing a usbredir peer to write past the end of the packet descriptor array on every subsequent isochronous packet. The vulnerability was disclosed on September 17, 2026, and was reported by Calif.io. Red Hat has assessed that this vulnerability does not affect any currently supported Red Hat product. The CVSS category is estimated as HIGH (Red Hat CVE, Feedly).
The root cause is an out-of-bounds write (CWE-787) in the usbredirhost_iso_packet() function within the usbredir library. When an isochronous OUT stream is initialized with a transfer count of exactly 1, the sole transfer buffer is never submitted, which causes the internal bounds check to be permanently bypassed. As a result, every subsequent isochronous packet from a usbredir peer can write beyond the end of the iso_packet_desc[] array, leading to a heap out-of-bounds write condition. Exploitation requires network-level access to a usbredir peer endpoint, making it relevant primarily in virtualized or remote USB redirection scenarios (Red Hat CVE, Red Hat Bugzilla).
Successful exploitation of this vulnerability can result in heap memory corruption, which may lead to arbitrary code execution, denial of service (crash/exit), or undefined system state. An attacker with access to a usbredir peer connection could potentially modify control data such as return addresses to execute unauthorized code, or cause the affected process to crash. The impact is most significant in virtualized environments where USB redirection is enabled, as exploitation could affect the host or guest system integrity (Red Hat CVE).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for CVE-2026-92382 as of the time of disclosure. The CVE status is listed as "Reserved" and no EPSS score or CISA KEV catalog entry has been identified. Exploitation requires network access to a usbredir peer, limiting the attack surface to environments where USB redirection is actively in use (Red Hat CVE, Feedly).
Red Hat has determined that no currently supported Red Hat product is affected by this vulnerability. As a workaround, Red Hat recommends removing the usbredir package if USB redirection is not a required feature, which eliminates the attack surface but may impact USB device redirection functionality in virtualized environments. Organizations using usbredir in other contexts should monitor upstream usbredir project releases for patches and apply them promptly (Red Hat CVE).
Red Hat Product Security acknowledged the report and credited Calif.io for discovering and reporting the vulnerability. Red Hat explicitly noted that while the CVE is tracked in their database, it does not affect any currently supported Red Hat product, and their assessment may evolve with further analysis (Red Hat CVE).
Disponibilité des correctifs sur les principales distributions Linux et leurs versions.
bionic (esm-infra)
usbredir
devel
usbredir
focal (esm-infra)
usbredir
jammy
usbredir
noble
usbredir
resolute
usbredir
trusty (esm-infra-legacy)
usbredir
xenial (esm-infra-legacy)
usbredir
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."