Buffer Overflow Vulnerability in Linux Kernel Affects Multiple Products
CVE-2026-80568
Currently unrated
What is CVE-2026-80568?
A vulnerability exists in the Linux kernel related to the synaptics-rmi4 input handling. When changing the input while streaming data, the report size can change unexpectedly, leading to a potential heap buffer overflow if the new input's size exceeds the initially allocated buffer size. This risk is mitigated by implementing a block on the VIDIOC_S_INPUT call when the associated V4L2 queue is busy, ensuring more secure handling of input changes and preventing unauthorized memory access.
Affected Version(s)
Linux 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d < 7e994a9ecc0b49ad2fe63da9c92a8aca8a6614af
Linux 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d
Linux 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d < 493ba8e794729649689438edba72337111303cc4