SB20260727307 - Out-of-bounds write in Linux kernel joystick iforce driver
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Out-of-bounds write (CVE-ID: CVE-2026-64273)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 5.2 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows an attacker with physical access to corrupt kernel memory.
The vulnerability exists due to an out-of-bounds write in iforce_process_packet() when processing a device-reported force-feedback status packet. An attacker with physical access can supply a crafted device payload with an out-of-range effect index to corrupt kernel memory.
The issue affects both USB interrupt endpoint and serio transports, and the status handling path is not gated on force-feedback support being present.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/0e9943d2e4c63496b6ca84bc66fd3c71d40558e2
- https://git.kernel.org/stable/c/6c0f2901c9d325d4a0574c4237fd507810d225ff
- https://git.kernel.org/stable/c/70019779325f2bb5f5a4098e91e79c655f50fcef
- https://git.kernel.org/stable/c/a40250f97c312e000e3616c9074022311a0efbc3
- https://git.kernel.org/stable/c/b1b79e89bc33e4c682d3df7ae2aadc62b5a0c310
- https://git.kernel.org/stable/c/c21295616a8a52b9a5f18cd4ca8c73030eda3d4f
- https://git.kernel.org/stable/c/d10b0507fa0f5b46764b178e3271f9012f2df677
- https://git.kernel.org/stable/c/e5fa31f0550b55d80045669ae9080dd5b88abffa