CVE-2026-64272
In the Linux kernel, the following vulnerability has been resolved:
Input: mms114 - fix touch indexing for MMS134S and MMS136
The MMS134S and MMS136 touch controllers have an event size of 6 bytes rather than 8 bytes. When __mms114_read_reg() reads the touch data packet from the device into the touch buffer, the events are packed tightly at 6-byte intervals. However, the driver iterates through the events using standard C array indexing (touch[index]), where each element is sizeof(struct mms114_touch) (8 bytes) apart. As a result, any touch events beyond the first one are read from incorrect offsets and parsed improperly.
Read full descriptionShow less
Fix this by explicitly calculating the byte offset for each touch event based on the device's specific event size.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Base score: 7.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.17%
- Percentile among all scored CVEs: 6
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
🎯 ATT&CK techniques
How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.
- Exploitation
T1068Exploitation for Privilege Escalationprivilege escalation75 % - Primary impact
T1005Data from Local Systemcollection60 % - Secondary impact
T1565Data Manipulationimpact55 %
Acceso local (AV:L) sin UI:R permite escalada de privilegios mediante lectura/manipulación de datos de entrada táctil sin validar (CWE-129: Improper Validation of Array Index).
Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.
🛡️ ATT&CK mitigations that cover these techniques
Affected technologies (1)
CWEs
- CWE-129
References
- https://git.kernel.org/stable/c/062bbe55a1f6d77b89d07135ba3b09f97bfac1cb
- https://git.kernel.org/stable/c/112666835071d935fef764aab590339e97216d4a
- https://git.kernel.org/stable/c/38de2979d90d8cd94f18e0567be4c8342d0e0410
- https://git.kernel.org/stable/c/75b12874b4172533b9efc349db328cb1a59c3981
- https://git.kernel.org/stable/c/7c00a0787af7164438bdbc97fcae9733cfc58d21
- https://git.kernel.org/stable/c/a6ac4e24c1a8a533bb61035184fdcc7eede4cc8d
- https://git.kernel.org/stable/c/a747c4eb02656afdbd92eea83b88e92715a23977
Raw JSON (NVD)
Show
{
"id": "CVE-2026-64272",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "53fefdd1d3a3403d8c44e28898d1031d8763b913",
"lessThan": "062bbe55a1f6d77b89d07135ba3b09f97bfac1cb",
"versionType": "git"
},
{
"status": "affected",
"version": "53fefdd1d3a3403d8c44e28898d1031d8763b913",
"lessThan": "38de2979d90d8cd94f18e0567be4c8342d0e0410",
"versionType": "git"
},
{
"status": "affected",
"version": "53fefdd1d3a3403d8c44e28898d1031d8763b913",
"lessThan": "112666835071d935fef764aab590339e97216d4a",
"versionType": "git"
},
{
"status": "affected",
"version": "53fefdd1d3a3403d8c44e28898d1031d8763b913",
"lessThan": "7c00a0787af7164438bdbc97fcae9733cfc58d21",
"versionType": "git"
},
{
"status": "affected",
"version": "53fefdd1d3a3403d8c44e28898d1031d8763b913",
"lessThan": "75b12874b4172533b9efc349db328cb1a59c3981",
"versionType": "git"
},
{
"status": "affected",
"version": "53fefdd1d3a3403d8c44e28898d1031d8763b913",
"lessThan": "a747c4eb02656afdbd92eea83b88e92715a23977",
"versionType": "git"
},
{
"status": "affected",
"version": "53fefdd1d3a3403d8c44e28898d1031d8763b913",
"lessThan": "a6ac4e24c1a8a533bb61035184fdcc7eede4cc8d",
"versionType": "git"
}
],
"programFiles": [
"drivers/input/touchscreen/mms114.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "5.13"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "5.13",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.145",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.96",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.39",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.4",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/input/touchscreen/mms114.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-07-25T10:17:07.550",
"references": [
{
"url": "https://git.kernel.org/stable/c/062bbe55a1f6d77b89d07135ba3b09f97bfac1cb",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/112666835071d935fef764aab590339e97216d4a",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/38de2979d90d8cd94f18e0567be4c8342d0e0410",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/75b12874b4172533b9efc349db328cb1a59c3981",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/7c00a0787af7164438bdbc97fcae9733cfc58d21",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a6ac4e24c1a8a533bb61035184fdcc7eede4cc8d",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/a747c4eb02656afdbd92eea83b88e92715a23977",
"tags": [
"Patch"
],
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-129"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: mms114 - fix touch indexing for MMS134S and MMS136\n\nThe MMS134S and MMS136 touch controllers have an event size of 6 bytes\nrather than 8 bytes. When __mms114_read_reg() reads the touch data\npacket from the device into the touch buffer, the events are packed\ntightly at 6-byte intervals. However, the driver iterates through the\nevents using standard C array indexing (touch[index]), where each\nelement is sizeof(struct mms114_touch) (8 bytes) apart. As a result, any\ntouch events beyond the first one are read from incorrect offsets and\nparsed improperly.\n\nFix this by explicitly calculating the byte offset for each touch event\nbased on the device's specific event size."
}
],
"lastModified": "2026-08-23T13:16:31.400",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A8617408-1AB4-4CBE-BC49-5A1EAAFE7233",
"versionEndExcluding": "6.6.145",
"versionStartIncluding": "5.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "38A8100E-2B1A-462F-AEE9-8901B870FEF2",
"versionEndExcluding": "6.12.96",
"versionStartIncluding": "6.7"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "914AE4BC-3D59-4C5A-9DB5-9CE327B429F7",
"versionEndExcluding": "6.18.39",
"versionStartIncluding": "6.13"
},
{
"criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6228DDD6-4557-4AA3-9F43-AB995D471E42",
"versionEndExcluding": "7.1.4",
"versionStartIncluding": "6.19"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}