Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-80569

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
26/08/2026
Última modificación:
27/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer<br /> <br /> rmi_f54_work() reads a diagnostics report from the device into<br /> f54-&gt;report_data, sizing the transfer with rmi_f54_get_report_size():<br /> <br /> report_size = rmi_f54_get_report_size(f54);<br /> ...<br /> for (i = 0; i report_data + i, size);<br /> }<br /> <br /> report_data is allocated once at probe from F54&amp;#39;s own electrode counts<br /> (array3_size(f54-&gt;num_tx_electrodes, f54-&gt;num_rx_electrodes, sizeof(u16))),<br /> but rmi_f54_get_report_size() computes the size from<br /> drv_data-&gt;num_*_electrodes when those are set, i.e. from the F55<br /> function&amp;#39;s electrode counts. Both counts come straight from device<br /> queries (F54 and F55 each report up to 255 electrodes) and nothing<br /> constrains the F55 counts to the F54 ones.<br /> <br /> A malicious or malfunctioning RMI4 device that reports larger F55<br /> electrode counts than its F54 counts makes report_size exceed the<br /> allocation, so the read loop writes past report_data (and the V4L2<br /> dequeue memcpy() then reads past it). On conforming hardware the F55<br /> configured electrodes are a subset of the F54 physical electrodes, so<br /> report_size never exceeds the buffer and well-behaved devices are<br /> unaffected.<br /> <br /> Record the allocation size and reject a report that does not fit,<br /> mirroring the existing zero-size check.