CVE-2026-64270

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/07/2026
Last modified:
30/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> Input: mms114 - reject an oversized device packet size<br /> <br /> mms114_interrupt() reads a packet of touch data from the device into a<br /> fixed-size on-stack buffer<br /> <br /> struct mms114_touch touch[MMS114_MAX_TOUCH];<br /> <br /> which holds MMS114_MAX_TOUCH (10) events of MMS114_EVENT_SIZE (8) bytes,<br /> i.e. 80 bytes. The length of the I2C read into it is taken verbatim from<br /> the device:<br /> <br /> packet_size = mms114_read_reg(data, MMS114_PACKET_SIZE);<br /> if (packet_size

Impact