Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-63908

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
19/07/2026
Última modificación:
27/07/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem<br /> <br /> When a configuration file provides an object size that is larger than the<br /> driver&amp;#39;s known mxt_obj_size(object), the driver intends to discard the<br /> extra bytes.<br /> <br /> The loop iterates using for (i = 0; i mxt_obj_size(object))<br /> continue;<br /> <br /> Since i is a 0-based index, the valid indices for the object are 0 through<br /> mxt_obj_size(object) - 1.<br /> <br /> When i == mxt_obj_size(object), the condition evaluates to false, and the<br /> code processes the byte instead of discarding it.<br /> <br /> This causes the code to calculate byte_offset = reg + i - cfg-&gt;start_ofs<br /> and writes the byte there, overwriting exactly one byte of the adjacent<br /> instance or object.<br /> <br /> Update the boundary check to skip extra bytes correctly by using &gt;=.

Impacto