SB20260727295 - Out-of-bounds read in Linux kernel input rmi4 driver
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds read (CVE-ID: CVE-2026-64277)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information and overwrite adjacent kernel memory.
The vulnerability exists due to an out-of-bounds read and out-of-bounds write in the synaptics-rmi4 F3A GPIO keymap handling in drivers/input/rmi4/rmi_f3a.c when processing a device that reports a gpio_count greater than the allocated keymap size. A local user can open the evdev node and invoke keymap ioctls to disclose sensitive information and overwrite adjacent kernel memory.
The information disclosure occurs through EVIOCGKEYCODE leaking adjacent slab memory to user space, while EVIOCSKEYCODE writes a caller-controlled value past the buffer.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/3480e24bc4e178aaa009edb25b6ee12df199e210
- https://git.kernel.org/stable/c/35ed74d32d8260bdfb14a94caf402bf0866bdeec
- https://git.kernel.org/stable/c/502ad7caaa1a445b734c827fa256e5311df67e3d
- https://git.kernel.org/stable/c/57c10915f2c16c90e0d46ad00876bf39ece40fc2
- https://git.kernel.org/stable/c/64fb0e1161ccc6b9e48b8df61f07d3c34c01ec42
- https://git.kernel.org/stable/c/850117b637bcb1dcc14be0cf09ac819a8707b42c
- https://git.kernel.org/stable/c/8db211aed83733073b0814adaeeab61d4521474e
- https://git.kernel.org/stable/c/ba57f430328534501962d60d651e385ffd7af9ca