SB20260727310 - Integer underflow in Linux kernel input mouse driver
Published: July 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Integer underflow (CVE-ID: CVE-2026-64275)
CWE-ID: CWE-191 - Integer underflow
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local attacker to disclose sensitive information.
The vulnerability exists due to integer underflow in the touch reporting logic of the elan_i2c touchpad driver when handling small calculated or fallback width values. A local attacker can cause width values smaller than ETP_FWIDTH_REDUCE to trigger an underflow and report a massive unsigned integer to userspace.
The issue affects touch width reporting to userspace.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/01e0317c256c560d8dcce2e9825eb6142ee34611
- https://git.kernel.org/stable/c/2f281ff0163a38fdc4cb4061f0c241e643283a5e
- https://git.kernel.org/stable/c/59d4cc5e7a9785e4bdc9c55273274c6b49d4b58d
- https://git.kernel.org/stable/c/6bac57d8fe2a077b8a85b4140eeb7999078158eb
- https://git.kernel.org/stable/c/8c1db3418a419e788691746b9c47f863c2fd4890
- https://git.kernel.org/stable/c/df2b818fa009c10ff6ba875a1663ff001cda9558
- https://git.kernel.org/stable/c/f6d10af2036d1d4a847a74fe47ebbf93bce3c84c
- https://git.kernel.org/stable/c/feb4866a42ec94764c7eb58012256f6f37664727