What is CVE-2026-63409?
Deskflow keyboard and mouse sharing app versions from 1.17.0 up to continuous build 1.26.0.296 are vulnerable to an out-of-bounds read in `ServerProxy::setOptions()` via a maliciously crafted odd-length DSOP vector. This could lead to potential information disclosure or denial-of-service on affected clients. Users should upgrade Deskflow to a version newer than 1.26.0.296 where the vulnerability is addressed.
Azərbaycanca: Deskflow klaviatura və siçan paylaşma proqramının 1.17.0-dən 1.26.0.296 versiyasına qədər olan aralığında server tərəfindən göndərilən xüsusi hazırlanmış DSOP vektoru `ServerProxy::setOptions()` funksiyasında bufer hüdudlarından kənar oxunmaya səbəb olur. Bu, təsirlənmiş müştərilərdə potensial məlumat sızması və ya xidmət xarici vəziyyətə (DoS) gətirib çıxara bilər. İstifadəçilərə Deskflow-u bu zəifliyin aradan qaldırıldığı 1.26.0.296-dən sonrakı versiyalara yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-125
FAQ2
Which versions of Deskflow are affected by CVE-2026-63409?
Deskflow versions from 1.17.0 up to continuous build 1.26.0.296 are affected by this vulnerability.
What is required to exploit CVE-2026-63409 and what are the potential impacts?
A maliciously crafted odd-length DSOP vector sent by the server triggers an out-of-bounds read in the `ServerProxy::setOptions()` function, which could lead to potential information disclosure or denial-of-service (DoS).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.