UBUNTU-CVE-2025-32776

Source
https://ubuntu.com/security/CVE-2025-32776
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-32776.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2025-32776
Related
Published
2025-04-15T17:15:00Z
Modified
2025-04-23T15:16:48Z
Summary
[none]
Details

OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linux. By writing specially crafted data to the matrix_custom_frame file, an attacker can cause the custom kernel driver to read more bytes than provided by user space. This data will be written into the RGB arguments which will be sent to the USB device. This issue has been patched in v3.10.2.

References

Affected packages

Ubuntu:20.04:LTS / openrazer

Package

Name
openrazer
Purl
pkg:deb/ubuntu/openrazer@2.5.0+dfsg-1ubuntu2?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.5.0+dfsg-1ubuntu2

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:22.04:LTS / openrazer

Package

Name
openrazer
Purl
pkg:deb/ubuntu/openrazer@3.2.0+dfsg-3?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.9.0+dfsg-1ubuntu1

3.*

3.2.0+dfsg-3

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.10 / openrazer

Package

Name
openrazer
Purl
pkg:deb/ubuntu/openrazer@3.8.0+dfsg-1?arch=source&distro=oracular

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.7.0+dfsg-1
3.8.0+dfsg-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:24.04:LTS / openrazer

Package

Name
openrazer
Purl
pkg:deb/ubuntu/openrazer@3.7.0+dfsg-1?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.4.0+dfsg-1ubuntu1
3.6.1+dfsg-1
3.7.0+dfsg-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}

Ubuntu:25.04 / openrazer

Package

Name
openrazer
Purl
pkg:deb/ubuntu/openrazer@3.10.0+dfsg-1?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*

3.8.0+dfsg-1
3.9.0+dfsg-1
3.10.0+dfsg-1

Ecosystem specific

{
    "ubuntu_priority": "medium"
}