Out-of-bounds read in Linux kernel - CVE-2026-46232
Published: May 29, 2026
Linux kernel
Detailed vulnerability description
The vulnerability allows an attacker with physical access to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in dualshock4_parse_report when processing a crafted HID report from a malicious device. An attacker with physical access can provide a device that misreports the number of touch reports to disclose sensitive information.
Data is exposed via evdev when the DS4_TOUCH_POINT_INACTIVE bit is set.
How to mitigate CVE-2026-46232
Sources
- https://git.kernel.org/stable/c/0bc4cf1a6ba00fb8c074531b179bc7b97502fbc4
- https://git.kernel.org/stable/c/208f6d5b1dfd6399bc6af9e11f27f1f496243ed0
- https://git.kernel.org/stable/c/7812694752a5f295eaa05a093b90a2c332666051
- https://git.kernel.org/stable/c/9c031b24aed6733b6dcc5d98527875b8654a04e9
- https://git.kernel.org/stable/c/cac61b58a3b6340c52afa06bb15eac033158db2f