Source: deskflow
Version: 1.26.0+dfsg-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for deskflow.

CVE-2026-63409[0]:
| Deskflow is a keyboard and mouse sharing app. From 1.17.0 until
| continuous build 1.26.0.296, a malicious Deskflow server can send an
| odd-length DSOP vector to ServerProxy::setOptions() in
| src/lib/client/ServerProxy.cpp, causing the missing value after the
| final option key to be read beyond the vector during the
| PacketStreamFilter::filterEvent to ServerProxy::handleData() to
| ServerProxy::parseHandshakeMessage() call chain and crash the
| connected client. This issue is fixed in continuous build
| 1.26.0.296.


CVE-2026-65832[1]:
| Deskflow is a keyboard and mouse sharing app. Prior to continuous
| build 1.26.0.299, a remote unauthenticated Deskflow server can send
| kMsgDSetOptions (DSOP) values to ServerProxy::setOptions() in
| src/lib/client/ServerProxy.cpp so that the value following a
| modifier option poisons m_modifierTranslationTable, after which
| ServerProxy::translateKey() or ServerProxy::translateModifierMask()
| indexes the seven-row s_translationTable or s_masks arrays out of
| bounds, disclosing four bytes at an attacker-selected relative
| offset or crashing the connected client; an odd option count also
| causes an out-of-bounds OptionsList read. This issue is fixed in
| continuous build 1.26.0.299.


CVE-2026-65976[2]:
| Deskflow is a keyboard and mouse sharing app. From 1.17.0 until
| continuous build 1.26.0.300, a connected peer can send repeated DCLP
| DataChunk messages to ClipboardChunk::assemble() in
| src/lib/deskflow/ClipboardChunk.cpp, causing the server path in
| src/lib/server/ClientProxy1_6.cpp or client path in
| src/lib/client/ServerProxy.cpp to append data beyond the DataStart
| declared size and configured clipboard limit before DataEnd
| validation, exhausting receiver memory. This issue is fixed in
| continuous build 1.26.0.300.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-63409
    https://www.cve.org/CVERecord?id=CVE-2026-63409
[1] https://security-tracker.debian.org/tracker/CVE-2026-65832
    https://www.cve.org/CVERecord?id=CVE-2026-65832
[2] https://security-tracker.debian.org/tracker/CVE-2026-65976
    https://www.cve.org/CVERecord?id=CVE-2026-65976

Regards,
Salvatore

Reply via email to