Hi,
The following vulnerabilities were published for openrgb.
While in Debian we do not ship a system service, but only a systemd
user service, the issues remain (limited to the privileges of the user
running the process), cf [3].
CVE-2026-59682[0]:
| Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This
| issue affects OpenRGB through 1.0rc3.
CVE-2026-59683[1]:
| The OpenRGB network protocol allows to write attacker controlled
| strings into arbitrary file system paths (extension of
| CVE-2026-59682). This allows either a full system compromise from
| local or remote (if the daemon is running as root) or a full account
| takeover (if the daemon is running in user context).
CVE-2026-18794[2]:
| The OpenRGB network protocol allows attackers to cause memory
| exhaustion and out-of-bounds memory reads and writes by passing
| inconsistent data.
If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-59682
https://www.cve.org/CVERecord?id=CVE-2026-59682
[1] https://security-tracker.debian.org/tracker/CVE-2026-59683
https://www.cve.org/CVERecord?id=CVE-2026-59683
[2] https://security-tracker.debian.org/tracker/CVE-2026-18794
https://www.cve.org/CVERecord?id=CVE-2026-18794
[3] https://www.openwall.com/lists/oss-security/2026/08/25/4
Regards,
Salvatore