Source: openrgb Version: 0.9+git20251009+ds-1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerabilities were published for openrgb. While in Debian we do not ship a system service, but only a systemd user service, the issues remain (limited to the privileges of the user running the process), cf [3]. CVE-2026-59682[0]: | Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This | issue affects OpenRGB through 1.0rc3. CVE-2026-59683[1]: | The OpenRGB network protocol allows to write attacker controlled | strings into arbitrary file system paths (extension of | CVE-2026-59682). This allows either a full system compromise from | local or remote (if the daemon is running as root) or a full account | takeover (if the daemon is running in user context). CVE-2026-18794[2]: | The OpenRGB network protocol allows attackers to cause memory | exhaustion and out-of-bounds memory reads and writes by passing | inconsistent data. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-59682 https://www.cve.org/CVERecord?id=CVE-2026-59682 [1] https://security-tracker.debian.org/tracker/CVE-2026-59683 https://www.cve.org/CVERecord?id=CVE-2026-59683 [2] https://security-tracker.debian.org/tracker/CVE-2026-18794 https://www.cve.org/CVERecord?id=CVE-2026-18794 [3] https://www.openwall.com/lists/oss-security/2026/08/25/4 Regards, Salvatore

