CVE-2026-80569
In the Linux kernel, the following vulnerability has been resolved:
Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer
rmi_f54_work() reads a diagnostics report from the device into f54->report_data, sizing the transfer with rmi_f54_get_report_size():
report_data is allocated once at probe from F54's own electrode counts (array3_size(f54->num_tx_electrodes, f54->num_rx_electrodes, sizeof(u16))), but rmi_f54_get_report_size() computes the size from drv_data->num_*_electrodes when those are set, i.e. from the F55 function's electrode counts. Both counts come straight from device queries (F54 and F55 each report up to 255 electrodes) and nothing constrains the F55 counts to the F54 ones.
Leer descripción completaMostrar menos
A malicious or malfunctioning RMI4 device that reports larger F55 electrode counts than its F54 counts makes report_size exceed the allocation, so the read loop writes past report_data (and the V4L2 dequeue memcpy() then reads past it). On conforming hardware the F55 configured electrodes are a subset of the F54 physical electrodes, so report_size never exceeds the buffer and well-behaved devices are unaffected.
Record the allocation size and reject a report that does not fit, mirroring the existing zero-size check.
Detalles técnicos trazas, registros y código del informe original
report_size = rmi_f54_get_report_size(f54);
...
for (i = 0; i < report_size; i += F54_REPORT_DATA_SIZE) {
int size = min(F54_REPORT_DATA_SIZE, report_size - i);
...
rmi_read_block(.., f54->report_data + i, size);
}CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.18%
- Percentil entre todas las CVEs puntuadas: 6
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1068Exploitation for Privilege Escalationprivilege escalation85 % - Impacto principal
T1083File and Directory Discoverydiscovery75 % - Impacto secundario
T1005Data from Local Systemcollection70 %
Acceso local (AV:L) sin interacción del usuario (UI:N) en kernel Linux. Buffer overflow en lectura de datos de dispositivo RMI4 permite leer/escribir memoria del kernel.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
Referencias
- https://git.kernel.org/stable/c/12be3c6ca9589afd6ade41a59c761866e526634d
- https://git.kernel.org/stable/c/42eaf0e6f79c487f419737314cf0760f7331d368
- https://git.kernel.org/stable/c/49c5adc2b7d6e43c5cf033e1c86fdb9c16ababb1
- https://git.kernel.org/stable/c/6b06aab79ff166d5781ce792d91acc2e58b1770b
- https://git.kernel.org/stable/c/6b3bdd44d4cd7d5e35de1d0f06d4930f3cecd403
- https://git.kernel.org/stable/c/b2f596f00d27703ce09167201ba57f55be8d2f9a
- https://git.kernel.org/stable/c/b3932101c9c457148038392bc977f9b31e125a86
- https://git.kernel.org/stable/c/b7b9a8b1c303b62371698e396654d6724c79cb74
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-80569",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
"affectedData": [
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "c762cc68b6a12eedebefc156ea4838e54804e2eb",
"lessThan": "6b3bdd44d4cd7d5e35de1d0f06d4930f3cecd403",
"versionType": "git"
},
{
"status": "affected",
"version": "c762cc68b6a12eedebefc156ea4838e54804e2eb",
"lessThan": "b2f596f00d27703ce09167201ba57f55be8d2f9a",
"versionType": "git"
},
{
"status": "affected",
"version": "c762cc68b6a12eedebefc156ea4838e54804e2eb",
"lessThan": "b3932101c9c457148038392bc977f9b31e125a86",
"versionType": "git"
},
{
"status": "affected",
"version": "c762cc68b6a12eedebefc156ea4838e54804e2eb",
"lessThan": "12be3c6ca9589afd6ade41a59c761866e526634d",
"versionType": "git"
},
{
"status": "affected",
"version": "c762cc68b6a12eedebefc156ea4838e54804e2eb",
"lessThan": "42eaf0e6f79c487f419737314cf0760f7331d368",
"versionType": "git"
},
{
"status": "affected",
"version": "c762cc68b6a12eedebefc156ea4838e54804e2eb",
"lessThan": "6b06aab79ff166d5781ce792d91acc2e58b1770b",
"versionType": "git"
},
{
"status": "affected",
"version": "c762cc68b6a12eedebefc156ea4838e54804e2eb",
"lessThan": "b7b9a8b1c303b62371698e396654d6724c79cb74",
"versionType": "git"
},
{
"status": "affected",
"version": "c762cc68b6a12eedebefc156ea4838e54804e2eb",
"lessThan": "49c5adc2b7d6e43c5cf033e1c86fdb9c16ababb1",
"versionType": "git"
}
],
"programFiles": [
"drivers/input/rmi4/rmi_f54.c"
],
"defaultStatus": "unaffected"
},
{
"repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
"vendor": "Linux",
"product": "Linux",
"versions": [
{
"status": "affected",
"version": "4.10"
},
{
"status": "unaffected",
"version": "0",
"lessThan": "4.10",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "5.10.266",
"versionType": "semver",
"lessThanOrEqual": "5.10.*"
},
{
"status": "unaffected",
"version": "5.15.217",
"versionType": "semver",
"lessThanOrEqual": "5.15.*"
},
{
"status": "unaffected",
"version": "6.1.184",
"versionType": "semver",
"lessThanOrEqual": "6.1.*"
},
{
"status": "unaffected",
"version": "6.6.153",
"versionType": "semver",
"lessThanOrEqual": "6.6.*"
},
{
"status": "unaffected",
"version": "6.12.105",
"versionType": "semver",
"lessThanOrEqual": "6.12.*"
},
{
"status": "unaffected",
"version": "6.18.46",
"versionType": "semver",
"lessThanOrEqual": "6.18.*"
},
{
"status": "unaffected",
"version": "7.1.10",
"versionType": "semver",
"lessThanOrEqual": "7.1.*"
},
{
"status": "unaffected",
"version": "7.2",
"versionType": "original_commit_for_fix",
"lessThanOrEqual": "*"
}
],
"programFiles": [
"drivers/input/rmi4/rmi_f54.c"
],
"defaultStatus": "affected"
}
]
}
],
"published": "2026-08-26T15:17:12.457",
"references": [
{
"url": "https://git.kernel.org/stable/c/12be3c6ca9589afd6ade41a59c761866e526634d",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/42eaf0e6f79c487f419737314cf0760f7331d368",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/49c5adc2b7d6e43c5cf033e1c86fdb9c16ababb1",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6b06aab79ff166d5781ce792d91acc2e58b1770b",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/6b3bdd44d4cd7d5e35de1d0f06d4930f3cecd403",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b2f596f00d27703ce09167201ba57f55be8d2f9a",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b3932101c9c457148038392bc977f9b31e125a86",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
},
{
"url": "https://git.kernel.org/stable/c/b7b9a8b1c303b62371698e396654d6724c79cb74",
"source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}
],
"vulnStatus": "Received",
"descriptions": [
{
"lang": "en",
"value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - bound the F54 report size to the allocated buffer\n\nrmi_f54_work() reads a diagnostics report from the device into\nf54->report_data, sizing the transfer with rmi_f54_get_report_size():\n\n\treport_size = rmi_f54_get_report_size(f54);\n\t...\n\tfor (i = 0; i < report_size; i += F54_REPORT_DATA_SIZE) {\n\t\tint size = min(F54_REPORT_DATA_SIZE, report_size - i);\n\t\t...\n\t\trmi_read_block(.., f54->report_data + i, size);\n\t}\n\nreport_data is allocated once at probe from F54's own electrode counts\n(array3_size(f54->num_tx_electrodes, f54->num_rx_electrodes, sizeof(u16))),\nbut rmi_f54_get_report_size() computes the size from\ndrv_data->num_*_electrodes when those are set, i.e. from the F55\nfunction's electrode counts. Both counts come straight from device\nqueries (F54 and F55 each report up to 255 electrodes) and nothing\nconstrains the F55 counts to the F54 ones.\n\nA malicious or malfunctioning RMI4 device that reports larger F55\nelectrode counts than its F54 counts makes report_size exceed the\nallocation, so the read loop writes past report_data (and the V4L2\ndequeue memcpy() then reads past it). On conforming hardware the F55\nconfigured electrodes are a subset of the F54 physical electrodes, so\nreport_size never exceeds the buffer and well-behaved devices are\nunaffected.\n\nRecord the allocation size and reject a report that does not fit,\nmirroring the existing zero-size check."
}
],
"lastModified": "2026-08-27T06:17:42.103",
"sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}