OpenRazer is an open source driver and user-space daemon to control Razer device lighting and other features on GNU/Linux. Using a modified USB device an attacker can leak stack addresses of the `razer_attr_read_dpi_stages`, potentially bypassing KASLR. To exploit this vulnerability an attacker would need to access to a users keyboard or mouse or would need to convince a user to use a modified device. The issue has been patched in v3.5.1. Users are advised to upgrade and should be reminded not to plug in unknown USB devices.
History

Wed, 23 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-12-05T19:22:30.988Z

Updated: 2025-04-23T16:32:45.096Z

Reserved: 2022-01-19T21:23:53.756Z

Link: CVE-2022-23467

cve-icon Vulnrichment

Updated: 2024-08-03T03:43:46.002Z

cve-icon NVD

Status : Modified

Published: 2022-12-05T20:15:10.133

Modified: 2024-11-21T06:48:37.200

Link: CVE-2022-23467

cve-icon Redhat

No data.