{"id":"AZL-105338","summary":"CVE-2026-92382 affecting package usbredir 0.13.0-1","details":"An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves the stream's single transfer buffer permanently unsubmitted, defeating the bounds check in usbredirhost_iso_packet() and allowing a usbredir peer to write past the end of the packet descriptor array on every subsequent isochronous packet.","modified":"2026-10-03T05:35:10Z","published":"2026-09-21T18:17:14Z","upstream":["CVE-2026-92382"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-92382"}],"affected":[{"package":{"name":"usbredir","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/usbredir"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.13.0-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105338.json"}}],"schema_version":"1.9.0"}