Out-of-bounds write in Linux kernel - CVE-2026-43047
Published: May 2, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows an attacker with physical access to cause a denial of service or perform an out-of-bounds write.
The vulnerability exists due to an out-of-bounds write in the HID multitouch feature report handling when processing a device response to a feature request. An attacker with physical access can provide a malicious device that responds with a mismatched report ID to cause a denial of service or perform an out-of-bounds write.
The issue is triggered when a device returns a different report ID than the one originally requested.
How to mitigate CVE-2026-43047
Sources
- https://git.kernel.org/stable/c/2edc92f89eee328b5be5706b5d431bf90669e9c0
- https://git.kernel.org/stable/c/516da3f25cfe18643835af1cf09b0e9ffc36c383
- https://git.kernel.org/stable/c/6a4acd3e86fe5584050c213d95147eba33856033
- https://git.kernel.org/stable/c/74c6015375d8b9bc1b1eb79f20636c8e894bcad7
- https://git.kernel.org/stable/c/7f66fdbc077faed3b52519228d21d81979e92249
- https://git.kernel.org/stable/c/a61163daf8a90b4a7ef154d5fc9c525f665734e3
- https://git.kernel.org/stable/c/c7a27bb4d0f6573ca0f9c7ef0b63291486239190
- https://git.kernel.org/stable/c/e716edafedad4952fe3a4a273d2e039a84e8681a