8.8

CVE-2026-64364

HID: multitouch: fix out-of-bounds bit access on mt_io_flags

In the Linux kernel, the following vulnerability has been resolved:

HID: multitouch: fix out-of-bounds bit access on mt_io_flags

mt_io_flags is a single unsigned long, but mt_process_slot(),
mt_release_pending_palms() and mt_release_contacts() use it as a
per-slot bitmap indexed by the slot number. That slot number is only
bounded by td->maxcontacts, which is taken from the device's
ContactCountMaximum feature report and can be up to 255, not by
BITS_PER_LONG.

As a result, a multitouch device that advertises a large contact count
makes set_bit()/clear_bit() operate past the mt_io_flags word and
corrupt the adjacent members of struct mt_device. The sticky-fingers
release timer is the easiest way to reach this. mt_release_contacts()
runs

	for (i = 0; i < mt->num_slots; i++)
		clear_bit(i, &td->mt_io_flags);

with num_slots == maxcontacts. For maxcontacts around 250 the loop
clears the bits that overlap td->applications.next, zeroing that list
head, and the list_for_each_entry() that immediately follows then
dereferences NULL. The kernel panics from timer (softirq) context. On a
KASAN build this shows up as a general protection fault in
mt_release_contacts() with a null-ptr-deref at offset 0x58, which is
offsetof(struct mt_application, num_received).

The state is reachable from an untrusted USB or Bluetooth HID
multitouch device; no local privileges are required.

Store the per-slot active state in a separately allocated bitmap sized
for maxcontacts, the same pattern already used for pending_palm_slots,
and keep only MT_IO_FLAGS_RUNNING in mt_io_flags. The two
"mt_io_flags & MT_IO_SLOTS_MASK" arming checks become
bitmap_empty(td->active_slots, td->maxcontacts).

Move MT_IO_FLAGS_RUNNING back to bit 0. It was bumped to bit 32 by the
same commit to leave the low byte for the slot bits; with the slot bits
gone it fits in bit 0 again, which also keeps it within the unsigned
long on 32-bit.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version fc488f675344931ffab6a51c43691065ec006567
Version < 12e90656e330ff8bbaf2f29c535fdb8a11cc6f55
Status affected
Version 77711d850bed75ae7142c3d1f22c1a8b4d049c33
Version < 152983d87387f6a8ae72b73474cfa55fbcf1ec75
Status affected
Version 6acfe25968913788d30ec0eedd80178c4ea3f1d0
Version < b5c037d6b807017e74a115288f81bc9cd5a5aab8
Status affected
Version d280c138e66be87d1fccfed42593f02fdb893905
Version < a6d5ce2e1a2d7bf189bde8a659d04b65f0b0725d
Status affected
Version f32fea4c0234c971c12e46d76612cdc2dd4bb046
Version < e24918ee67c4dc3d20d4670750e46e9b160365f4
Status affected
Version 46f781e0d151844589dc2125c8cce3300546f92a
Version < 37daa8c96bd563d03150e23f094cb60703594a6d
Status affected
Version 46f781e0d151844589dc2125c8cce3300546f92a
Version < 6493ebf9489efef0105078377b973ab33d51af22
Status affected
Version 46f781e0d151844589dc2125c8cce3300546f92a
Version < 8813b0612275cc61fe9e6603d0ee019247ade6be
Status affected
Version 59bd04163e6451b9c7275277882ed9f4abfa2051
Status affected
Version 5.10.246
Version < 5.10.261
Status affected
Version 5.15.196
Version < 5.15.212
Status affected
Version 6.1.158
Version < 6.1.178
Status affected
Version 6.6.114
Version < 6.6.145
Status affected
Version 6.12.55
Version < 6.12.97
Status affected
Version 6.17.5
Version < 6.18
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 6.18
Status affected
Version 0
Version < 6.18
Status unaffected
Version <= 5.10.*
Version 5.10.261
Status unaffected
Version <= 5.15.*
Version 5.15.212
Status unaffected
Version <= 6.1.*
Version 6.1.178
Status unaffected
Version <= 6.6.*
Version 6.6.145
Status unaffected
Version <= 6.12.*
Version 6.12.97
Status unaffected
Version <= 6.18.*
Version 6.18.39
Status unaffected
Version <= 7.1.*
Version 7.1.4
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.27
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/12e90656e330ff8bbaf2f29c535fdb8a11cc6f55
https://git.kernel.org/stable/c/152983d87387f6a8ae72b73474cfa55fbcf1ec75
https://git.kernel.org/stable/c/b5c037d6b807017e74a115288f81bc9cd5a5aab8
https://git.kernel.org/stable/c/a6d5ce2e1a2d7bf189bde8a659d04b65f0b0725d
https://git.kernel.org/stable/c/e24918ee67c4dc3d20d4670750e46e9b160365f4
https://git.kernel.org/stable/c/37daa8c96bd563d03150e23f094cb60703594a6d
https://git.kernel.org/stable/c/6493ebf9489efef0105078377b973ab33d51af22
https://git.kernel.org/stable/c/8813b0612275cc61fe9e6603d0ee019247ade6be