SerialiseValue in RenderDoc before 1.27 allows an Integer Overflow with a resultant Buffer Overflow. 0xffffffff is sign-extended to 0xffffffffffffffff (SIZE_MAX) and then there is an attempt to add 1.
{
"binaries": [
{
"binary_name": "librenderdoc",
"binary_version": "1.18+dfsg-1"
},
{
"binary_name": "librenderdoc-dev",
"binary_version": "1.18+dfsg-1"
},
{
"binary_name": "python3-renderdoc",
"binary_version": "1.18+dfsg-1"
},
{
"binary_name": "qrenderdoc",
"binary_version": "1.18+dfsg-1"
},
{
"binary_name": "renderdoc",
"binary_version": "1.18+dfsg-1"
},
{
"binary_name": "renderdoccmd",
"binary_version": "1.18+dfsg-1"
}
]
}