CVE-2026-80566
In the Linux kernel, the following vulnerability has been resolved:
Input: hynitron_cstxxx - validate touch count and finger IDs
The driver allocates max_touch_num input slots, which are indexed from zero through max_touch_num - 1. The current check allows a finger ID equal to max_touch_num to reach cst3xx_report_contact(). While the input core ignores out-of-range slot indices, reporting touch data without a valid slot change corrupts the touch state of the previously active slot.
The touch count is read from the controller's report and is used to index the fixed-size report buffer without first checking its range. Reject counts larger than the supported number of touch slots before checking the trailing byte or parsing touch data.
Leer descripción completaMostrar menos
Reject finger IDs equal to or greater than max_touch_num, and return immediately when an invalid finger ID is encountered so that corrupt touch frames are discarded instead of reporting partial contact state.
The V821 Avaota F1 board configures the vendor driver with one touch slot, so finger ID 1 is already invalid on that device.
CVSS
NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.16%
- Percentil entre todas las CVEs puntuadas: 4
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/27f380ef0e1d3de3cde114e02d33f9320ce3a5a6
- https://git.kernel.org/stable/c/387829ee60de26c7c073ed4e27ecfab2b75d4c74
- https://git.kernel.org/stable/c/38e7d5c1ade04b99c70da0298ca296ee62bc99c0
- https://git.kernel.org/stable/c/51c5503554c87e4de4035468bebf186205391ce9
- https://git.kernel.org/stable/c/ec61ca4e310665816a639cb2e46cd9b3af0a9bee
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80566",
"cveTags": [],
"metrics": {},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "66603243f5283f7f28c795f09e7c2167233df0bd",
"lessThan": "ec61ca4e310665816a639cb2e46cd9b3af0a9bee",
"versionType": "git"
},
{
"status": "affected",
"version": "66603243f5283f7f28c795f09e7c2167233df0bd",
"lessThan": "387829ee60de26c7c073ed4e27ecfab2b75d4c74",
"versionType": "git"
},
{
"status": "affected",
"version": "66603243f5283f7f28c795f09e7c2167233df0bd",
"lessThan": "38e7d5c1ade04b99c70da0298ca296ee62bc99c0",
"versionType": "git"
},
{
"status": "affected",
"version": "66603243f5283f7f28c795f09e7c2167233df0bd",
"lessThan": "51c5503554c87e4de4035468bebf186205391ce9",
"versionType": "git"
},
{
"status": "affected",
"version": "66603243f5283f7f28c795f09e7c2167233df0bd",
"lessThan": "27f380ef0e1d3de3cde114e02d33f9320ce3a5a6",
"versionType": "git"
}
],
"programFiles": [
"drivers/input/touchscreen/hynitron_cstxxx.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "6.2"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "6.2",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/input/touchscreen/hynitron_cstxxx.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-26T15:17:11.727",
"references": [
{
"url": "https://git.kernel.org/stable/c/27f380ef0e1d3de3cde114e02d33f9320ce3a5a6",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/387829ee60de26c7c073ed4e27ecfab2b75d4c74",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/38e7d5c1ade04b99c70da0298ca296ee62bc99c0",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/51c5503554c87e4de4035468bebf186205391ce9",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/ec61ca4e310665816a639cb2e46cd9b3af0a9bee",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: hynitron_cstxxx - validate touch count and finger IDs\n\nThe driver allocates max_touch_num input slots, which are indexed from\nzero through max_touch_num - 1. The current check allows a finger ID\nequal to max_touch_num to reach cst3xx_report_contact(). While the input\ncore ignores out-of-range slot indices, reporting touch data without a\nvalid slot change corrupts the touch state of the previously active slot.\n\nThe touch count is read from the controller's report and is used to\nindex the fixed-size report buffer without first checking its range.\nReject counts larger than the supported number of touch slots before\nchecking the trailing byte or parsing touch data.\n\nReject finger IDs equal to or greater than max_touch_num, and return\nimmediately when an invalid finger ID is encountered so that corrupt\ntouch frames are discarded instead of reporting partial contact state.\n\nThe V821 Avaota F1 board configures the vendor driver with one touch\nslot, so finger ID 1 is already invalid on that device."
}
],
"lastModified": "2026-08-26T15:17:11.727",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}