Heap-based buffer overflow in Linux kernel - CVE-2026-80568

 

Heap-based buffer overflow in Linux kernel - CVE-2026-80568

Published: August 27, 2026


Vulnerability identifier: #VU145922
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-80568
CWE-ID: CWE-122
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to a heap-based buffer overflow in the synaptics-rmi4 F54 V4L2 input handling when changing the diagnostic report input while streaming. A local user can switch the input mid-stream to trigger a larger report size than the allocated buffers and execute arbitrary code.

The issue occurs because V4L2 buffers are allocated based on the report size at stream start.


Affected software

Linux kernel

How to mitigate CVE-2026-80568

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins