[Git][security-tracker-team/security-tracker][master] Add CVE-2026-92382/usbredir
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Sep 21 04:57:47 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c6f6a22d by Salvatore Bonaccorso at 2026-09-21T05:57:23+02:00
Add CVE-2026-92382/usbredir
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,7 @@
+CVE-2026-92382 [usbredir: usbredir: unbounded iso_packet_desc[] index in usbredirhost_iso_packet() leads to heap out-of-bounds write]
+ - usbredir <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2535972
+ TODO: check details once Red Hat opens up bugzilla entry
CVE-2026-94113 (Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contai ...)
NOT-FOR-US: Frappe ERPNext
CVE-2026-94112 (mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c6f6a22dbaf3a237dbd29894db36d6944a63dd82
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c6f6a22dbaf3a237dbd29894db36d6944a63dd82
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260921/f94a21cd/attachment.htm>
More information about the debian-security-tracker-commits
mailing list