Out-of-bounds read in Linux kernel - CVE-2026-64277
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information and overwrite adjacent kernel memory.
The vulnerability exists due to an out-of-bounds read and out-of-bounds write in the synaptics-rmi4 F3A GPIO keymap handling in drivers/input/rmi4/rmi_f3a.c when processing a device that reports a gpio_count greater than the allocated keymap size. A local user can open the evdev node and invoke keymap ioctls to disclose sensitive information and overwrite adjacent kernel memory.
The information disclosure occurs through EVIOCGKEYCODE leaking adjacent slab memory to user space, while EVIOCSKEYCODE writes a caller-controlled value past the buffer.
Affected software
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for Real Time
Red Hat Enterprise Linux for Real Time for NFV
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Ubuntu
kernel (Red Hat package)
kernel-rt (Red Hat package)
linux (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
How to mitigate CVE-2026-64277
kernel (Red Hat package) - addressed in versions 4.18.0-553.158.1.el8_10, 5.14.0-687.42.1.el9_8, 6.12.0-211.50.1.el10_2
kernel-rt (Red Hat package) - update to 4.18.0-553.158.1.rt7.499.el8_10
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
External References
- https://git.kernel.org/stable/c/3480e24bc4e178aaa009edb25b6ee12df199e210
- https://git.kernel.org/stable/c/35ed74d32d8260bdfb14a94caf402bf0866bdeec
- https://git.kernel.org/stable/c/502ad7caaa1a445b734c827fa256e5311df67e3d
- https://git.kernel.org/stable/c/57c10915f2c16c90e0d46ad00876bf39ece40fc2
- https://git.kernel.org/stable/c/64fb0e1161ccc6b9e48b8df61f07d3c34c01ec42
- https://git.kernel.org/stable/c/850117b637bcb1dcc14be0cf09ac819a8707b42c
- https://git.kernel.org/stable/c/8db211aed83733073b0814adaeeab61d4521474e
- https://git.kernel.org/stable/c/ba57f430328534501962d60d651e385ffd7af9ca
Related Security Bulletins
- Out-of-bounds read in Linux kernel input rmi4 driver
- Red Hat Enterprise Linux 9 update for kernel
- Red Hat Enterprise Linux 8 update for kernel-rt
- Red Hat Enterprise Linux 8 update for kernel
- Red Hat Enterprise Linux 10 update for kernel
- Ubuntu update for linux-oem-7.0
- Ubuntu update for linux
- Ubuntu update for linux-gcp-7.0