OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linux. By writing specially crafted data to the `matrix_custom_frame` file, an attacker can cause the custom kernel driver to read more bytes than provided by user space. This data will be written into the RGB arguments which will be sent to the USB device. This issue has been patched in v3.10.2.
Metrics
Affected Vendors & Products
References
History
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 15 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Apr 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linux. By writing specially crafted data to the `matrix_custom_frame` file, an attacker can cause the custom kernel driver to read more bytes than provided by user space. This data will be written into the RGB arguments which will be sent to the USB device. This issue has been patched in v3.10.2. | |
| Title | OpenRazer Vulnerable to Out of Bounds Read | |
| Weaknesses | CWE-125 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-04-15T16:32:20.628Z
Updated: 2025-11-03T19:53:39.183Z
Reserved: 2025-04-10T12:51:12.278Z
Link: CVE-2025-32776
Updated: 2025-11-03T19:53:39.183Z
Status : Awaiting Analysis
Published: 2025-04-15T17:15:49.730
Modified: 2025-11-03T20:18:28.297
Link: CVE-2025-32776
No data.