7.8

CVE-2026-80568

Input: synaptics-rmi4 - block s_input when F54 queue is busy

In the Linux kernel, the following vulnerability has been resolved:

Input: synaptics-rmi4 - block s_input when F54 queue is busy

Changing the input (diagnostic report type) mid-stream changes the
report size. Since V4L2 buffers are allocated based on the size at
stream start, changing the input while streaming could lead to a
heap buffer overflow if the new size is larger than the allocated
buffers.

Prevent this by blocking VIDIOC_S_INPUT with -EBUSY if the V4L2 queue
is busy (streaming).
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
≫
Produkt Linux
Default Statusunaffected
Version 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d
Version < 7e994a9ecc0b49ad2fe63da9c92a8aca8a6614af
Status affected
Version 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d
Version < fa69f93015becf3729716de2199b58540aa99672
Status affected
Version 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d
Version < 493ba8e794729649689438edba72337111303cc4
Status affected
Version 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d
Version < 1d718f1461766e9f00a8dbeb4f13f1b1c19d90ac
Status affected
Version 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d
Version < cae79513f9115c350561b16f36adcb47c9bfff12
Status affected
Version 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d
Version < ff0849705d29277fd1f6fc6596674b9308724fb2
Status affected
Version 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d
Version < ddd9a53faf3b65e5920cb802cb1db6f4615bdfef
Status affected
Version 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d
Version < fbfd76746adc16d64be29ff113f673b70bc3f5c2
Status affected
HerstellerLinux
≫
Produkt Linux
Default Statusaffected
Version 4.9
Status affected
Version 0
Version < 4.9
Status unaffected
Version <= 5.10.*
Version 5.10.266
Status unaffected
Version <= 5.15.*
Version 5.15.217
Status unaffected
Version <= 6.1.*
Version 6.1.184
Status unaffected
Version <= 6.6.*
Version 6.6.153
Status unaffected
Version <= 6.12.*
Version 6.12.105
Status unaffected
Version <= 6.18.*
Version 6.18.46
Status unaffected
Version <= 7.1.*
Version 7.1.10
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.031
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/7e994a9ecc0b49ad2fe63da9c92a8aca8a6614af
https://git.kernel.org/stable/c/fa69f93015becf3729716de2199b58540aa99672
https://git.kernel.org/stable/c/493ba8e794729649689438edba72337111303cc4
https://git.kernel.org/stable/c/1d718f1461766e9f00a8dbeb4f13f1b1c19d90ac
https://git.kernel.org/stable/c/cae79513f9115c350561b16f36adcb47c9bfff12
https://git.kernel.org/stable/c/ff0849705d29277fd1f6fc6596674b9308724fb2
https://git.kernel.org/stable/c/ddd9a53faf3b65e5920cb802cb1db6f4615bdfef
https://git.kernel.org/stable/c/fbfd76746adc16d64be29ff113f673b70bc3f5c2