CVE-2026-64271
Analyzed Analyzed - Analysis Complete

Buffer Overflow in Linux Kernel Touchscreen Driver

Vulnerability report for CVE-2026-64271, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-25

Last updated on: 2026-08-13

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: Input: touchwin - reset the packet index on every complete packet tw_interrupt() accumulates each non-zero serial byte into a fixed three-byte buffer with a running index that is only reset once a full packet has been received *and* the device's two Y bytes agree: tw->data[tw->idx++] = data; if (tw->idx == TW_LENGTH && tw->data[1] == tw->data[2]) { ... tw->idx = 0; } The reset is gated on tw->data[1] == tw->data[2], a value the device controls. A malicious, malfunctioning or counterfeit Touchwindow peripheral can stream non-zero bytes whose 2nd and 3rd bytes differ: the index reaches TW_LENGTH without the equality holding, is never reset, and keeps growing, so tw->data[tw->idx++] walks off the end of the three-byte array and the rest of the heap-allocated struct tw, one attacker-chosen byte at a time -- an unbounded, device-driven heap out-of-bounds write. Reset the index on every completed packet and report an event only when the two Y bytes match, like the other serio touchscreen drivers do.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-25
Last Modified
2026-08-13
Generated
2026-08-14
AI Q&A
2026-07-25
EPSS Evaluated
2026-08-13
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
linux linux_kernel From 5.11 (inc) to 5.15.212 (exc)
linux linux_kernel From 5.16 (inc) to 6.1.178 (exc)
linux linux_kernel From 6.2 (inc) to 6.6.145 (exc)
linux linux_kernel From 6.7 (inc) to 6.12.96 (exc)
linux linux_kernel From 6.13 (inc) to 6.18.39 (exc)
linux linux_kernel From 6.19 (inc) to 7.1.4 (exc)
linux linux_kernel From 2.6.19 (inc) to 5.10.261 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-129 The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a heap out-of-bounds write vulnerability in the Linux kernel's Touchwindow driver. A malicious device can send malformed packets that cause the driver to write beyond the intended buffer by manipulating the packet index. The issue occurs because the index reset condition depends on device-controlled data, allowing unbounded writes to kernel memory.

Detection Guidance

This vulnerability affects the Linux kernel's handling of Touchwindow peripherals. Detection requires checking kernel logs for unusual serial device activity or heap corruption events. Monitor dmesg or journalctl for serio driver errors or out-of-bounds writes. No specific commands are provided in the context.

Impact Analysis

An attacker with access to a malicious Touchwindow device could exploit this to corrupt kernel memory, potentially causing system crashes, privilege escalation, or arbitrary code execution. This requires physical or local access to the affected system.

Compliance Impact

This vulnerability involves a heap out-of-bounds write in the Linux kernel's Touchwindow peripheral driver, which could allow an attacker to corrupt memory. Such memory corruption may lead to unauthorized data access or system instability, potentially violating data integrity and confidentiality requirements in standards like GDPR and HIPAA.

Mitigation Strategies

Apply the Linux kernel patch that resets the packet index on every complete packet. Update to a patched kernel version. Disable or disconnect any Touchwindow peripherals until patched. Monitor system logs for signs of exploitation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64271. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart