RenderDoc before 1.27 allows local privilege escalation via a symlink attack. It relies on the /tmp/RenderDoc directory regardless of ownership.
{
"binaries": [
{
"binary_name": "librenderdoc",
"binary_version": "1.18+dfsg-1"
},
{
"binary_name": "librenderdoc-dev",
"binary_version": "1.18+dfsg-1"
},
{
"binary_name": "python3-renderdoc",
"binary_version": "1.18+dfsg-1"
},
{
"binary_name": "qrenderdoc",
"binary_version": "1.18+dfsg-1"
},
{
"binary_name": "renderdoc",
"binary_version": "1.18+dfsg-1"
},
{
"binary_name": "renderdoccmd",
"binary_version": "1.18+dfsg-1"
}
]
}