Your message dated Wed, 26 Aug 2026 12:18:56 +0000
with message-id <[email protected]>
and subject line Bug#1145169: fixed in deskflow 1.26.0+dfsg-4
has caused the Debian Bug report #1145169,
regarding deskflow: CVE-2026-63409 CVE-2026-65832 CVE-2026-65976
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1145169: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1145169
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: deskflow
Version: 1.26.0+dfsg-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for deskflow.

CVE-2026-63409[0]:
| Deskflow is a keyboard and mouse sharing app. From 1.17.0 until
| continuous build 1.26.0.296, a malicious Deskflow server can send an
| odd-length DSOP vector to ServerProxy::setOptions() in
| src/lib/client/ServerProxy.cpp, causing the missing value after the
| final option key to be read beyond the vector during the
| PacketStreamFilter::filterEvent to ServerProxy::handleData() to
| ServerProxy::parseHandshakeMessage() call chain and crash the
| connected client. This issue is fixed in continuous build
| 1.26.0.296.


CVE-2026-65832[1]:
| Deskflow is a keyboard and mouse sharing app. Prior to continuous
| build 1.26.0.299, a remote unauthenticated Deskflow server can send
| kMsgDSetOptions (DSOP) values to ServerProxy::setOptions() in
| src/lib/client/ServerProxy.cpp so that the value following a
| modifier option poisons m_modifierTranslationTable, after which
| ServerProxy::translateKey() or ServerProxy::translateModifierMask()
| indexes the seven-row s_translationTable or s_masks arrays out of
| bounds, disclosing four bytes at an attacker-selected relative
| offset or crashing the connected client; an odd option count also
| causes an out-of-bounds OptionsList read. This issue is fixed in
| continuous build 1.26.0.299.


CVE-2026-65976[2]:
| Deskflow is a keyboard and mouse sharing app. From 1.17.0 until
| continuous build 1.26.0.300, a connected peer can send repeated DCLP
| DataChunk messages to ClipboardChunk::assemble() in
| src/lib/deskflow/ClipboardChunk.cpp, causing the server path in
| src/lib/server/ClientProxy1_6.cpp or client path in
| src/lib/client/ServerProxy.cpp to append data beyond the DataStart
| declared size and configured clipboard limit before DataEnd
| validation, exhausting receiver memory. This issue is fixed in
| continuous build 1.26.0.300.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-63409
    https://www.cve.org/CVERecord?id=CVE-2026-63409
[1] https://security-tracker.debian.org/tracker/CVE-2026-65832
    https://www.cve.org/CVERecord?id=CVE-2026-65832
[2] https://security-tracker.debian.org/tracker/CVE-2026-65976
    https://www.cve.org/CVERecord?id=CVE-2026-65976

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: deskflow
Source-Version: 1.26.0+dfsg-4
Done: Kentaro Hayashi <[email protected]>

We believe that the bug you reported is fixed in the latest version of
deskflow, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Kentaro Hayashi <[email protected]> (supplier of updated deskflow package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Format: 1.8
Date: Wed, 26 Aug 2026 19:51:36 +0900
Source: deskflow
Architecture: source
Version: 1.26.0+dfsg-4
Distribution: unstable
Urgency: medium
Maintainer: HAYASHI Kentaro <[email protected]>
Changed-By: Kentaro Hayashi <[email protected]>
Closes: 1145169
Changes:
 deskflow (1.26.0+dfsg-4) unstable; urgency=medium
 .
   * debian/patches/CVE-2026-63409.patch
     debian/patches/CVE-2026-65832.patch
     debian/patches/CVE-2026-65976-1.patch
     debian/patches/CVE-2026-65976-2.patch
     debian/patches/add-clipboard-size-setting.patch
     - Fix CVE-2026-63409, CVE-2026-63832 and CVE-2026-65976 (Closes: #1145169)
Checksums-Sha1:
 2246567d2698140468af4e104c93c9a4956ccb70 2403 deskflow_1.26.0+dfsg-4.dsc
 0bfcdfed3dc84a9db37b7601d8286ab3717998f2 742528 
deskflow_1.26.0+dfsg.orig.tar.xz
 9d6aa115933fdc6aa631b626d79b02f664db1f4d 13496 
deskflow_1.26.0+dfsg-4.debian.tar.xz
 3f70bad1757c9fb970f5d642b39b3e0f2615e2fa 15027 
deskflow_1.26.0+dfsg-4_source.buildinfo
Checksums-Sha256:
 a06639d1726c68ac5914f478bf0d3b6b5b01d1d4ff78c475058f77e11570bf9e 2403 
deskflow_1.26.0+dfsg-4.dsc
 1994407e03c22e6aaa46ab6b788396e0655161fad88a6de499752181f27dec46 742528 
deskflow_1.26.0+dfsg.orig.tar.xz
 052f6297f9b4bbb9069a78606b996794b3b6f933ae70a5ed9448dfe1295e7e8b 13496 
deskflow_1.26.0+dfsg-4.debian.tar.xz
 2ba37937860da560e04c726fadf37f610ca744c781985a82f153ecf679f61d6d 15027 
deskflow_1.26.0+dfsg-4_source.buildinfo
Files:
 90869ac7cbdf15b1c9d5140123398339 2403 x11 optional deskflow_1.26.0+dfsg-4.dsc
 4c6369abf2c5832300fdc82650aa2d77 742528 x11 optional 
deskflow_1.26.0+dfsg.orig.tar.xz
 db30d330a5c3ea8204c6944d6e22c564 13496 x11 optional 
deskflow_1.26.0+dfsg-4.debian.tar.xz
 aedc54edb0f62c84a03aba8a3614cd3e 15027 x11 optional 
deskflow_1.26.0+dfsg-4_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEcZ6y2T2+nE0h+6Bk9/t1xWbtIOMFAmqO1yUACgkQ9/t1xWbt
ION+DRAApyrbpuiDdhRN/CK83WaYML75GzIjYt09+VJbdcmY8GSs/qTnB0dK6Hbx
kKFVmcA5vtfGaicN4DXvvNZ3HbPQie1rKa+smQHrlN4WOjREuTW1uVF7m4FtcB9c
URep3hL7wSVTVz10p1zQhxeJWTbbI4A0GlKBQ/iw/gZ5x7PXASFE47THVgJ+SY7s
mTE3AIsSzd8lT03H59SNArTZltTOSbGkv3IVnFRHHyqavRxvidr2zrm1yQFyyxcv
kw+wWVuR+VLA0kM/54BrHOj+ij1EkTaniEp+ASoWXnMhqYNGMw7GMYauUYEsUHzb
Y9/YK6iJK/g9TqD01ekIGL+6SNROK7L2aK4bZHoHkKPHVTA7slodOaJQ+GBfl0/g
6Q1p7nMSO4A/TBorInw24FsVXFWynb1/dxgKoXKf81yhr4Zbxf2NPYUr2AT+Fve2
bj/57k2AKXo/vgP3k6XmBc3vrvbXLsIIcwOswVrWQyH0yJ4/NDtfTzMhHIulMJW+
z+SJbH74OZzWB7S6xFN9uSKKSaiKQZPU710mBieKLTzLqgcKOcxNKJvrWqMQZwzt
1BmBLz3QaJPlkXxrw2wK6BjH8yEpaPKBynYBJtXM12hkHSbecgNqUfDXuzS1EJrO
o24WHFxF3qbN7l5PsRJ7i0a8bFfNbozPuqvHH2spCqy5JBDiFn0=
=nO9D
-----END PGP SIGNATURE-----

Attachment: pgpLhapxZuQzS.pgp
Description: PGP signature


--- End Message ---

Reply via email to