protonscr

[CWE-190] When the type overflow is fixed? It is unsafe in Linux Steam

steamclosed
ValveSoftware/steam-for-linux#12550 · opened 2025-12-13 by GermanAizek · updated 2025-12-13 · 1 comments · github
GGermanAizek 2025-12-13 github

Your system information

  • Steam client version: 1763795278
  • Distribution: Devuan
  • Opted into Steam client beta?: No
  • Have you checked for system updates?: Yes
  • GPU: Intel Arc

Due to the fact that the client is 32-bit, it is very easy to exploit many "Integer Overflow" attacks (CWE-190 MITRE).
The Steam Client is too large a project, it is functionally complex, and since 2014 this type of vulnerability can be exploited, it is impossible to cover and fix all types for guard from IO until there is a 64-bit port.

References:

Kkisak-valve maintainer 2025-12-13 github

Hello @GermanAizek, if there's specific details for a Steam dev to ponder, please report security issues like this via a non-public medium like Steam Support. There's no point in tracking this in a generalized manner on this public issue tracker.

Nothing extracted yet.