Related Vulnerabilities: CVE-2021-3700  

An use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in usbredirparser_serialize() in usbredirparser/usbredirparser.c when serializing large amounts of buffered write data in case of a slow or blocked destination.

Severity Medium

Remote Yes

Type Arbitrary code execution

Description

An use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in usbredirparser_serialize() in usbredirparser/usbredirparser.c when serializing large amounts of buffered write data in case of a slow or blocked destination.

AVG-2279 usbredir 0.9.0-1 Medium Vulnerable FS#71803

https://bugzilla.redhat.com/show_bug.cgi?id=1992830
https://gitlab.freedesktop.org/spice/usbredir/-/commit/03c519ff5831ba75120e00ebebbf1d5a1f7220ab