PT-2025-16362 · Openrazer+1 · Openrazer+1

Diraltvein

·

Published

2025-04-15

·

Updated

2025-04-24

·

CVE-2025-32776

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenRazer versions prior to 3.10.2
Description The issue allows an attacker to cause the custom kernel driver to read more bytes than provided by user space by writing specially crafted data to the matrix custom frame file. This data will be written into the RGB arguments which will be sent to the USB device.
Recommendations For versions prior to 3.10.2, update to version 3.10.2 to resolve the issue. As a temporary workaround, consider restricting access to the matrix custom frame file to minimize the risk of exploitation.

Exploit

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

CVE-2025-32776
DLA-4136-1
GHSA-835J-6976-46JX

Affected Products

Debian
Openrazer