CVE-2026-64271

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/07/2026
Last modified:
30/07/2026

Description

In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> Input: touchwin - reset the packet index on every complete packet<br /> <br /> tw_interrupt() accumulates each non-zero serial byte into a fixed<br /> three-byte buffer with a running index that is only reset once a full<br /> packet has been received *and* the device&amp;#39;s two Y bytes agree:<br /> <br /> tw-&gt;data[tw-&gt;idx++] = data;<br /> if (tw-&gt;idx == TW_LENGTH &amp;&amp; tw-&gt;data[1] == tw-&gt;data[2]) {<br /> ...<br /> tw-&gt;idx = 0;<br /> }<br /> <br /> The reset is gated on tw-&gt;data[1] == tw-&gt;data[2], a value the device<br /> controls. A malicious, malfunctioning or counterfeit Touchwindow<br /> peripheral can stream non-zero bytes whose 2nd and 3rd bytes differ: the<br /> index reaches TW_LENGTH without the equality holding, is never reset, and<br /> keeps growing, so tw-&gt;data[tw-&gt;idx++] walks off the end of the three-byte<br /> array and the rest of the heap-allocated struct tw, one attacker-chosen<br /> byte at a time -- an unbounded, device-driven heap out-of-bounds write.<br /> <br /> Reset the index on every completed packet and report an event only when<br /> the two Y bytes match, like the other serio touchscreen drivers do.

Impact