CVE-2026-64270
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/07/2026
Last modified:
30/07/2026
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
Input: mms114 - reject an oversized device packet size<br />
<br />
mms114_interrupt() reads a packet of touch data from the device into a<br />
fixed-size on-stack buffer<br />
<br />
struct mms114_touch touch[MMS114_MAX_TOUCH];<br />
<br />
which holds MMS114_MAX_TOUCH (10) events of MMS114_EVENT_SIZE (8) bytes,<br />
i.e. 80 bytes. The length of the I2C read into it is taken verbatim from<br />
the device:<br />
<br />
packet_size = mms114_read_reg(data, MMS114_PACKET_SIZE);<br />
if (packet_size
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/5d2ea15ba03bf17ed143ff1a0995a4206edc3fb6
- https://git.kernel.org/stable/c/66725039f7090afe14c31bd259e2059a68f04023
- https://git.kernel.org/stable/c/8301c335305344d4da4ab9442b6a399dacfe5b8d
- https://git.kernel.org/stable/c/b78150729762d47c14fe29a2582bdca5568e62b8
- https://git.kernel.org/stable/c/f3d5e77b27fded71dcb97f409262bf0abba0410e



