SerialiseValue in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. 0xffffffff is sign-extended to 0xffffffffffffffff (SIZE_MAX) and then there is an attempt to add 1.
{
"binaries": [
{
"binary_version": "1.18+dfsg-1",
"binary_name": "librenderdoc"
},
{
"binary_version": "1.18+dfsg-1",
"binary_name": "librenderdoc-dev"
},
{
"binary_version": "1.18+dfsg-1",
"binary_name": "python3-renderdoc"
},
{
"binary_version": "1.18+dfsg-1",
"binary_name": "qrenderdoc"
},
{
"binary_version": "1.18+dfsg-1",
"binary_name": "renderdoc"
},
{
"binary_version": "1.18+dfsg-1",
"binary_name": "renderdoccmd"
}
]
}