CVE-2026-80569
Received Received - Intake

Buffer Overflow in Linux Kernel RMI4 Synaptics Driver

Vulnerability report for CVE-2026-80569, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-26

Last updated on: 2026-08-26

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer rmi_f54_work() reads a diagnostics report from the device into f54->report_data, sizing the transfer with rmi_f54_get_report_size(): report_size = rmi_f54_get_report_size(f54); ... for (i = 0; i < report_size; i += F54_REPORT_DATA_SIZE) { int size = min(F54_REPORT_DATA_SIZE, report_size - i); ... rmi_read_block(.., f54->report_data + i, size); } report_data is allocated once at probe from F54's own electrode counts (array3_size(f54->num_tx_electrodes, f54->num_rx_electrodes, sizeof(u16))), but rmi_f54_get_report_size() computes the size from drv_data->num_*_electrodes when those are set, i.e. from the F55 function's electrode counts. Both counts come straight from device queries (F54 and F55 each report up to 255 electrodes) and nothing constrains the F55 counts to the F54 ones. A malicious or malfunctioning RMI4 device that reports larger F55 electrode counts than its F54 counts makes report_size exceed the allocation, so the read loop writes past report_data (and the V4L2 dequeue memcpy() then reads past it). On conforming hardware the F55 configured electrodes are a subset of the F54 physical electrodes, so report_size never exceeds the buffer and well-behaved devices are unaffected. Record the allocation size and reject a report that does not fit, mirroring the existing zero-size check.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-26
Last Modified
2026-08-26
Generated
2026-08-26
AI Q&A
2026-08-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves a buffer overflow in the synaptics-rmi4 driver. The issue occurs when the F54 report size exceeds the allocated buffer due to mismatched electrode counts between F54 and F55 functions on a device. A malicious or malfunctioning device can exploit this to write past the buffer, potentially causing memory corruption or crashes.

Detection Guidance

This vulnerability is specific to Linux kernel Synaptics RMI4 touchpad drivers and requires checking kernel logs for buffer overflow errors related to synaptics-rmi4 or F54 report handling. Inspect dmesg for errors like 'report_data' overflow or out-of-bounds writes.

Impact Analysis

If exploited, this vulnerability could lead to system instability, crashes, or unauthorized memory access. On systems using RMI4 devices like touchpads, it might cause erratic behavior or denial of service. Well-behaved devices are unaffected as the F55 electrode counts are a subset of F54's.

Mitigation Strategies

Apply the latest Linux kernel updates that include the fix for this CVE. If immediate patching is not possible, disable the synaptics-rmi4 driver module or restrict access to RMI4 devices until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80569. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart