#1145783 openrgb: CVE-2026-59682 CVE-2026-59683 CVE-2026-18794

Package:
src:openrgb
Source:
src:openrgb
Submitter:
Salvatore Bonaccorso
Date:
2026-08-27 07:09:02 UTC
Severity:
normal
Tags:
#1145783#5
Date:
2026-08-27 07:07:02 UTC
From:
To:
Hi,

The following vulnerabilities were published for openrgb.

While in Debian we do not ship a system service, but only a systemd
user service, the issues remain (limited to the privileges of the user
running the process), cf [3].

CVE-2026-59682[0]:
| Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB. This
| issue affects OpenRGB through 1.0rc3.


CVE-2026-59683[1]:
| The OpenRGB network protocol allows to write attacker controlled
| strings into arbitrary file system paths (extension of
| CVE-2026-59682). This allows either a full system compromise from
| local or remote (if the daemon is running as root) or a full account
| takeover (if the daemon is running in user context).


CVE-2026-18794[2]:
| The OpenRGB network protocol allows attackers to cause memory
| exhaustion and out-of-bounds memory reads and writes by passing
| inconsistent data.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-59682
https://www.cve.org/CVERecord?id=CVE-2026-59682
[1] https://security-tracker.debian.org/tracker/CVE-2026-59683
https://www.cve.org/CVERecord?id=CVE-2026-59683
[2] https://security-tracker.debian.org/tracker/CVE-2026-18794
https://www.cve.org/CVERecord?id=CVE-2026-18794
[3] https://www.openwall.com/lists/oss-security/2026/08/25/4

Regards,
Salvatore