SB2026082762 - Out-of-bounds read in Linux kernel input misc driver



SB2026082762 - Out-of-bounds read in Linux kernel input misc driver

Published: August 27, 2026

Security Bulletin ID SB2026082762
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Out-of-bounds read (CVE-ID: CVE-2026-80575)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to an out-of-bounds read in the cs40l50-vibra driver when processing FF_PERIODIC/FF_CUSTOM effect data supplied through EVIOCSFF. A local user can provide a specially crafted custom data buffer to execute arbitrary code.

The issue can be triggered when the custom data buffer is shorter than the two words later read by the driver, and the bank value handling can also wrap values of 0x8000 or greater to a negative index.


Remediation

Install update from vendor's website.