Integer underflow in Linux kernel - CVE-2026-64275
Published: July 27, 2026
Vulnerability details
The vulnerability allows a local attacker to disclose sensitive information.
The vulnerability exists due to integer underflow in the touch reporting logic of the elan_i2c touchpad driver when handling small calculated or fallback width values. A local attacker can cause width values smaller than ETP_FWIDTH_REDUCE to trigger an underflow and report a massive unsigned integer to userspace.
The issue affects touch width reporting to userspace.
Affected software
Ubuntu
linux (Ubuntu package)
linux-gcp-7.0 (Ubuntu package)
linux-oem-7.0 (Ubuntu package)
How to mitigate CVE-2026-64275
linux (Ubuntu package) - addressed in versions 7.0.0-31.31, 7.0.0-31.31.1, 7.0.0-31.31~24.04.1, 7.0.0-1006.7, 7.0.0-1011.11~24.04.1, 7.0.0-1012.12, 7.0.0-1012.12~24.04.1
linux-gcp-7.0 (Ubuntu package) - update to 7.0.0-1011.11~24.04.1
linux-oem-7.0 (Ubuntu package) - update to 7.0.0-1013.13
External References
- https://git.kernel.org/stable/c/01e0317c256c560d8dcce2e9825eb6142ee34611
- https://git.kernel.org/stable/c/2f281ff0163a38fdc4cb4061f0c241e643283a5e
- https://git.kernel.org/stable/c/59d4cc5e7a9785e4bdc9c55273274c6b49d4b58d
- https://git.kernel.org/stable/c/6bac57d8fe2a077b8a85b4140eeb7999078158eb
- https://git.kernel.org/stable/c/8c1db3418a419e788691746b9c47f863c2fd4890
- https://git.kernel.org/stable/c/df2b818fa009c10ff6ba875a1663ff001cda9558
- https://git.kernel.org/stable/c/f6d10af2036d1d4a847a74fe47ebbf93bce3c84c
- https://git.kernel.org/stable/c/feb4866a42ec94764c7eb58012256f6f37664727