HIGH
Deskflow: Odd-length DSOP options vector causes out-of-bounds read in Deskflow client
Published Aug 17, 2026
8.2
HIGHCVSS 3.1
EPSS 0.45%
Description
Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malicious Deskflow server can send an odd-length DSOP vector to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp, causing the missing value after the final option key to be read beyond the vector during the PacketStreamFilter::filterEvent to ServerProxy::handleData() to ServerProxy::parseHandshakeMessage() call chain and crash the connected client. This issue is fixed in continuous build 1.26.0.296.
Affected products
-
- Version >= 1.17.0, < 1.26.0.296StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-60463 Advisory
- https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f x_refsource_MISC
- https://github.com/deskflow/deskflow/security/advisories/GHSA-gmvh-3c73-m5gg exploitx_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-60463 | Advisory | |
| https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f | x_refsource_MISC | |
| https://github.com/deskflow/deskflow/security/advisories/GHSA-gmvh-3c73-m5gg | exploitx_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 17, 2026
Updated Aug 18, 2026
Reserved Jul 16, 2026
Link CVE-2026-63409
CISA Vulnrichment
Updated Aug 18, 2026
ENISA EUVD
EUVD-2026-60463 Assigner GitHub_M
Published Aug 17, 2026
Updated Aug 18, 2026
Exploited since n/a
Link EUVD-2026-60463