#1145783 openrgb: CVE-2026-59682 CVE-2026-59683 CVE-2026-18794

Package:
src:openrgb
Source:
src:openrgb
Submitter:
Salvatore Bonaccorso
Date:
2026-10-05 16:07:03 UTC
Severity:
normal
Tags:
#1145783#5
Date:
2026-08-27 07:07:02 UTC
From:
To:
Hi,

The following vulnerabilities were published for openrgb.

While in Debian we do not ship a system service, but only a systemd
user service, the issues remain (limited to the privileges of the user
running the process), cf [3].

CVE-2026-59682[0]:
| Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This
| issue affects OpenRGB through 1.0rc3.


CVE-2026-59683[1]:
| The OpenRGB network protocol allows to write attacker controlled
| strings into arbitrary file system paths (extension of
| CVE-2026-59682). This allows either a full system compromise from
| local or remote (if the daemon is running as root) or a full account
| takeover (if the daemon is running in user context).


CVE-2026-18794[2]:
| The OpenRGB network protocol allows attackers to cause memory
| exhaustion and out-of-bounds memory reads and writes by passing
| inconsistent data.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-59682
https://www.cve.org/CVERecord?id=CVE-2026-59682
[1] https://security-tracker.debian.org/tracker/CVE-2026-59683
https://www.cve.org/CVERecord?id=CVE-2026-59683
[2] https://security-tracker.debian.org/tracker/CVE-2026-18794
https://www.cve.org/CVERecord?id=CVE-2026-18794
[3] https://www.openwall.com/lists/oss-security/2026/08/25/4

Regards,
Salvatore

#1145783#10
Date:
2026-10-01 04:28:01 UTC
From:
To:
Dear maintainer,

The CVEs mentioned in this bug report are all fixed with the version 1.0
of openrgb. I prepared an NMU to fix them in a clone of your Salse repo:

https://salsa.debian.org/olebole/openrgb

I updated the d/watch file for format version 5 and changed to the
standard "gitlab" template using tarballs in the hope of regular
releases. Apart from that I tried to be minimally invasive, leaving a
few issues unresolved (using outdated qt5, missing udev initialization,
user instead of system installation in systemd).

I plan to upload this NMU next week; however I am happy to hold it back
if you want to step in. I do not plan to maintain the package.

Best regards

Ole

#1145783#17
Date:
2026-10-05 16:04:51 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
openrgb, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1145783@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Ole Streicher <olebole@debian.org> (supplier of updated openrgb package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 30 Sep 2026 22:52:50 +0200
Source: openrgb
Architecture: source
Version: 1.0+ds-0.1
Distribution: unstable
Urgency: medium
Maintainer: Ahmad Khalifa <ahmad@khalifa.ws>
Changed-By: Ole Streicher <olebole@debian.org>
Closes: 1145783
Changes:
 openrgb (1.0+ds-0.1) unstable; urgency=medium
 .
   * Non-maintainer upload.
   * d/watch: switch to version 5, GitLab template
   * New upstream version 1.0+ds (Closes: #1145783)
    (CVE-2026-59682, CVE-2026-59683, CVE-2026-18794)
   * Rediff patches
Checksums-Sha1:
 43e6f4a0721e4953462f40d4aadfd2f61b5650a9 1999 openrgb_1.0+ds-0.1.dsc
 0cbbeb493b73ce6cddbd9974cf9c99a7c07972f7 1978332 openrgb_1.0+ds.orig.tar.xz
 481c5d477d40cd1cb7cafe80bd413ece159d3274 9268 openrgb_1.0+ds-0.1.debian.tar.xz
Checksums-Sha256:
 328d0e0dbe2124b02d6a188971f84556c700d17bed9e2913ed603293645c465e 1999 openrgb_1.0+ds-0.1.dsc
 008e8b124ebb0254330c2fa3cf75cd974574670d3b6d2252e3d7eef6c7d67f02 1978332 openrgb_1.0+ds.orig.tar.xz
 8b042b059c4fca2613a4ee7f4741987a55b2a6a6619a7b9c82e2803cfa2d99a1 9268 openrgb_1.0+ds-0.1.debian.tar.xz
Files:
 64e9e8bd4327c13751d83b810cec07cb 1999 misc optional openrgb_1.0+ds-0.1.dsc
 a7980350b8a70d450c88f653e05b84b0 1978332 misc optional openrgb_1.0+ds.orig.tar.xz
 2208644134504b310ddf6cb4b9916aa5 9268 misc optional openrgb_1.0+ds-0.1.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEuvxshffLFD/utvsVcRWv0HcQ3PcFAmrDxcAACgkQcRWv0HcQ
3Pc2sQ/7BF3yd+1WKlhoWnQOFrsT2xJmXGGf7dB/wNDAs37trqY0iw5s4Mmj7BPc
o/cAtf197ngX2BSdCEp98VzuLQPsDHewGwde3k8DxFVHKkLfs4vihqAK3NAL4a9z
rkMieUnG9bmyZqfB2eg65xwBpqRSFR3huUH4pVAYaScaIKNwdvye05nue15RYtdw
5avZAZoPq84C3deoxHeSiQ5hqlG8o2+gtOosvf/sF/kgb28KwFLY5OIswwOMdcHR
Hcj1TXxrb99xFlMeMPElc+P5z/2Np5f8V5YBYY11WxG+hoto730dSvm/r2FalfOL
+SKBy8Sk4uZuI6EA8XTQafnOEsexgdEyAXf/DmhOiLm3dz5EAXzyC5nVrYsSEnCL
sy2GStBimY24z61q00adLLlcCjOAEarN59Fl91o6AFB/f7i6XktBjs2rkDOVtyEk
qn1NwxRuI6xN6az8MFlzpvnMcmsYKJg0kQl/rWSNrK8tzEZ19hz0/4OaknaFUyA0
E6K9fIubBXKzZyHFDU6o+eGuAp4sCiVPx201ZSaL0jvBtdFv53PskCUsasj05lo4
oNbrlS/Ro7K3VEQDeihC75PVTpgL5jffnDlCAlKDjSfgfjHfsdKhV8HcjSyre0Cy
eOT9jXQwvfAdUnNY2m+1kpd1mMlZ8A2Kl8d5mCO31LuTk16qPj0=
=I7PU
-----END PGP SIGNATURE-----