DEBIAN-CVE-2025-32776

Source
https://security-tracker.debian.org/tracker/CVE-2025-32776
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-32776.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2025-32776
Upstream
Published
2025-04-15T17:15:49Z
Modified
2025-10-10T19:31:11.188493Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linux. By writing specially crafted data to the matrix_custom_frame file, an attacker can cause the custom kernel driver to read more bytes than provided by user space. This data will be written into the RGB arguments which will be sent to the USB device. This issue has been patched in v3.10.2.

References

Affected packages

Debian:11 / openrazer

Package

Name
openrazer
Purl
pkg:deb/debian/openrazer?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.9.0+dfsg-1+deb11u1

Affected versions

2.*

2.9.0+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / openrazer

Package

Name
openrazer
Purl
pkg:deb/debian/openrazer?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.5.1+dfsg-2+deb12u1

Affected versions

3.*

3.5.1+dfsg-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / openrazer

Package

Name
openrazer
Purl
pkg:deb/debian/openrazer?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.10.2+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:14 / openrazer

Package

Name
openrazer
Purl
pkg:deb/debian/openrazer?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.10.2+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}