PT-2026-76822 · Deskflow · Deskflow
CVE-2026-65832
·
Published
2026-08-17
·
Updated
2026-08-18
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Deskflow versions prior to 1.26.0.299
Description
A remote unauthenticated server can send
kMsgDSetOptions (DSOP) values to the setOptions() function in src/lib/client/ServerProxy.cpp. This action poisons the m modifierTranslationTable, leading the translateKey() or translateModifierMask() functions to index the s translationTable or s masks arrays out of bounds. This can result in the disclosure of four bytes at a relative offset selected by the attacker or cause the connected client to crash. Additionally, providing an odd option count triggers an out-of-bounds read of the OptionsList.Recommendations
Update to continuous build 1.26.0.299.
Exploit
Fix
Improper Validation of Array Index
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Deskflow