{"id":"CVE-2026-63409","summary":"Deskflow: Odd-length DSOP options vector causes out-of-bounds read in Deskflow client","details":"Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malicious Deskflow server can send an odd-length DSOP vector to ServerProxy::setOptions() in src/lib/client/ServerProxy.cpp, causing the missing value after the final option key to be read beyond the vector during the PacketStreamFilter::filterEvent to ServerProxy::handleData() to ServerProxy::parseHandshakeMessage() call chain and crash the connected client. This issue is fixed in continuous build 1.26.0.296.","aliases":["GHSA-gmvh-3c73-m5gg"],"modified":"2026-08-20T10:17:20.788636Z","published":"2026-08-17T20:57:19.326Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63409.json","unresolved_ranges":[{"extracted_events":[{"introduced":"1.17.0"},{"fixed":"1.26.0.296"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63409.json"},{"type":"ADVISORY","url":"https://github.com/deskflow/deskflow/security/advisories/GHSA-gmvh-3c73-m5gg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-63409"},{"type":"FIX","url":"https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/deskflow/deskflow","events":[{"introduced":"0"},{"fixed":"8266fbbe6af93fa370018886c7f1f35d2cee8b3f"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v1.26.0","v1.25.0","v1.24.0","v1.23.0","v1.22.0","v1.21.2","v1.21.1","v1.21.0","v1.20.1","v1.20.0","v1.19.0","v1.18.0","v1.17.2","v1.17.1","v1.17.0"],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["59296496970081143490392020132113578308","264147184473189989835777453027769399669","105461901912855228587267469831660350127","84147866730353443619115107668400347161"]},"id":"CVE-2026-63409-03a42dcc","signature_type":"Line","signature_version":"v1","source":"https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f","target":{"file":"src/lib/server/ClientProxy1_0.cpp"}},{"source":"https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f","target":{"file":"src/lib/client/Client.cpp"},"deprecated":false,"digest":{"line_hashes":["236976754671402044676543928600241033718","301820332396168299652958655454656578282","75656020767226221753543808461534719015","88737114258928579320783421213981706439"],"threshold":0.9},"id":"CVE-2026-63409-11dad1d3","signature_type":"Line","signature_version":"v1"},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f","target":{"file":"src/lib/deskflow/Screen.cpp"},"deprecated":false,"digest":{"line_hashes":["93452003649932511260159433311084409086","247688328563674058561963965487937275917","222930386684317508431460109957809265988","28762715122451522537557181752956634048"],"threshold":0.9},"id":"CVE-2026-63409-40e33c37"},{"deprecated":false,"digest":{"function_hash":"242150540230015351880935572870261266256","length":529},"id":"CVE-2026-63409-4211de9e","signature_type":"Function","signature_version":"v1","source":"https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f","target":{"file":"src/lib/platform/XWindowsScreen.cpp","function":"XWindowsScreen::setOptions"}},{"deprecated":false,"digest":{"function_hash":"46660015884301948534165028696470585037","length":1125},"id":"CVE-2026-63409-57e2ac2f","signature_type":"Function","signature_version":"v1","source":"https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f","target":{"file":"src/lib/client/ServerProxy.cpp","function":"ServerProxy::setOptions"}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f","target":{"file":"src/lib/client/ServerProxy.cpp"},"deprecated":false,"digest":{"line_hashes":["34153358309916817461995184018916692635","177866724128377571376130959453194049113","170436926807622728606035106478103507819"],"threshold":0.9},"id":"CVE-2026-63409-6859f86c"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f","target":{"file":"src/lib/client/Client.cpp","function":"Client::setOptions"},"deprecated":false,"digest":{"function_hash":"312139493942473756410202906392974875075","length":915},"id":"CVE-2026-63409-7d19d0e5"},{"source":"https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f","target":{"file":"src/lib/server/ClientProxy1_0.cpp","function":"ClientProxy1_0::setOptions"},"deprecated":false,"digest":{"function_hash":"104530485550888798731996742964881974822","length":541},"id":"CVE-2026-63409-929b8799","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"length":1080,"function_hash":"18947052360808800384892180812294548188"},"id":"CVE-2026-63409-a61be1d9","signature_type":"Function","signature_version":"v1","source":"https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f","target":{"file":"src/lib/deskflow/Screen.cpp","function":"Screen::setOptions"}},{"deprecated":false,"digest":{"line_hashes":["273541962625817997133142657194574257165","202300633054273446961833766744508583768","337889412725806583931295026569644801833","26441519965697055416038752529846435248"],"threshold":0.9},"id":"CVE-2026-63409-aa93e63b","signature_type":"Line","signature_version":"v1","source":"https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f","target":{"file":"src/lib/platform/XWindowsScreen.cpp"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63409.json","vanir_signatures_modified":"2026-08-20T10:17:20Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"}]}