SB2026082768 - Heap-based buffer overflow in Linux kernel input rmi4 driver



SB2026082768 - Heap-based buffer overflow in Linux kernel input rmi4 driver

Published: August 27, 2026

Security Bulletin ID SB2026082768
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Heap-based buffer overflow (CVE-ID: CVE-2026-80568)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to a heap-based buffer overflow in the synaptics-rmi4 F54 V4L2 input handling when changing the diagnostic report input while streaming. A local user can switch the input mid-stream to trigger a larger report size than the allocated buffers and execute arbitrary code.

The issue occurs because V4L2 buffers are allocated based on the report size at stream start.


Remediation

Install update from vendor's website.