Heap Buffer Overflow in Linux Kernel Affects Synaptics RMI4
CVE-2026-80570

Currently unrated

Key Information:

Vendor

Linux

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-80570?

A vulnerability in the Synaptics RMI4 component of the Linux kernel allows for a heap buffer overflow due to incorrect error handling. When an error occurs during the report request or command verification process, the system improperly bypasses the intended error handling route, leaving the previous payload size intact. This can lead to issues when the V4L2 format is altered, as a subsequent failure may cause the system to copy a stale larger payload size to a smaller buffer, resulting in a buffer overflow. The vulnerability has been addressed by ensuring that the payload size is reset to zero on failure, thus preventing exploitation.

Affected Version(s)

Linux 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d < 62079c17ec07d64362bec367ee7a525b0dbf6bf9

Linux 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d < 79521ed3cc9ea48476666ccacf45ecd6954b29a4

Linux 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.