Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-80574

Gravedad CVSS v3.1:
ALTA
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
26/08/2026
Última modificación:
27/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet<br /> <br /> Make finger2 (and also finger1) unsigned, so that if the finger index in<br /> the packet is 0 then subtracting 1 creates an array index which overflows<br /> above the existing check for FOC_MAX_FINGERS, as the existing comment says<br /> it should, instead of writing to state-&gt;fingers[-1].