SB2026082768 - Heap-based buffer overflow in Linux kernel input rmi4 driver
Published: August 27, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Heap-based buffer overflow (CVE-ID: CVE-2026-80568)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow in the synaptics-rmi4 F54 V4L2 input handling when changing the diagnostic report input while streaming. A local user can switch the input mid-stream to trigger a larger report size than the allocated buffers and execute arbitrary code.
The issue occurs because V4L2 buffers are allocated based on the report size at stream start.
Remediation
Install update from vendor's website.
References
- https://git.kernel.org/stable/c/1d718f1461766e9f00a8dbeb4f13f1b1c19d90ac
- https://git.kernel.org/stable/c/493ba8e794729649689438edba72337111303cc4
- https://git.kernel.org/stable/c/7e994a9ecc0b49ad2fe63da9c92a8aca8a6614af
- https://git.kernel.org/stable/c/cae79513f9115c350561b16f36adcb47c9bfff12
- https://git.kernel.org/stable/c/ddd9a53faf3b65e5920cb802cb1db6f4615bdfef
- https://git.kernel.org/stable/c/fa69f93015becf3729716de2199b58540aa99672
- https://git.kernel.org/stable/c/fbfd76746adc16d64be29ff113f673b70bc3f5c2
- https://git.kernel.org/stable/c/ff0849705d29277fd1f6fc6596674b9308724fb2