CVE-2026-64014

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2026
Last modified:
19/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size<br /> <br /> nexio_read_data() pulls data_len and x_len from a packed __be16 header<br /> in the device&amp;#39;s interrupt packet and then walks packet-&gt;data[0..x_len)<br /> and packet-&gt;data[x_len..data_len) comparing each byte against a<br /> threshold.<br /> <br /> Both fields are 16-bit on the wire (max 65535). The existing<br /> adjustments shave at most 0x100 / 0x80 off, so the loop bound can still<br /> reach roughly 0xfeff. The URB transfer buffer for NEXIO is rept_size<br /> (1024) bytes from usb_alloc_coherent(), with the first 7 occupied by the<br /> packed header — so packet-&gt;data[] has 1017 valid bytes. read_data()<br /> callbacks are not given urb-&gt;actual_length, and nothing else bounds the<br /> walk.<br /> <br /> A device that lies about its length can get a ~64 KiB out-of-bounds read<br /> past the coherent DMA allocation. The first index whose byte exceeds<br /> NEXIO_THRESHOLD lands in begin_x / begin_y and from there into the<br /> reported touch coordinates, so adjacent kernel memory contents leak to<br /> userspace as ABS_X / ABS_Y events. Far enough out, the read can also<br /> hit an unmapped page and fault.<br /> <br /> Fix this all by clamping data_len to the buffer&amp;#39;s data[] capacity and<br /> x_len to data_len.

Impact