Out-of-Bounds Write Vulnerability in ELAN TrackPoint Driver
CVE-2026-14256

5.7MEDIUM

What is CVE-2026-14256?

The ELAN TrackPoint driver has been identified to potentially allow an out-of-bounds write vulnerability. Under specific circumstances, this vulnerability can be exploited by a local authenticated user, potentially leading to a system crash. Users and administrators should remain vigilant and ensure that their systems are updated with the latest security patches to mitigate this risk.

Affected Version(s)

100w Gen 4 Laptop (Lenovo) ELAN TrackPoint Driver for Windows 11 (Version 22H2 or later) - Lenovo 100w Gen 4, 300w Yoga Gen 4, 500w Yoga Gen 4 0 < 27.4.17.1

100w Gen 5 (Type 83LD, 83LE) Laptop (Lenovo) ELAN TrackPoint Driver for Windows 11 (Version 23H2 or later) - Lenovo 100w Gen 5, 300w 2-in-1 Gen 5, 500w 2-in-1 Gen 5 0 < 27.4.17.1

11e Yoga Gen 6 (Type 20SE, 20SF) Laptop (ThinkPad) Elan ClickPad Driver for Windows 11 (Version 21H2 or later), 10 (Version 1809 or later) - ThinkPad Yoga 11e 6th Gen 0 <= 24.21.50.4

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Lenovo thanks Shuqiao Zhang of Tsinghua University for reporting this vulnerability.
.