CVE-2026-19576
Received Received - Intake

Buffer Overflow in Goodix GT9xx Input Driver

Vulnerability report for CVE-2026-19576, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: Zephyr Project

Description

The Goodix GT9xx input driver in drivers/input/input_gt911.c reads the touch point count from the controller's status register and masks it with GT911_TOUCH_POINTS_MSK (0x0F), yielding a value of 0..15. In gt911_process() that value is used directly as the loop bound for filling point_reg[], a stack array sized to CONFIG_INPUT_GT911_MAX_TOUCH_POINTS, whose Kconfig range is 1..5 with a default of 1. No other check constrains the count; the driver relied only on a comment asserting that the controller had been programmed at init to report no more points than configured. Each loop iteration issues an I2C read of eight bytes straight into point_reg[i], so a controller that reports more points than the array holds causes up to 112 bytes of peer-supplied data to be written past the end of the array, over the stack frame of gt911_process() in the system workqueue thread. Two further loops then read out of bounds from the same array. Triggering it requires control of, or the ability to substitute, the I2C touch controller β€” plausible on the many supported boards where the GT9xx panel is a pluggable display module or shield rather than an on-PCB part; a spoofed device need only answer the init probes with a supported product ID and a checksum-valid config blob. The same overflow can also occur non-adversarially, with a GT9271-class panel that ignores the driver's touch-count programming and reports up to ten points, or with bus corruption of the single status byte. The impact is an out-of-bounds stack write with fully attacker-chosen content executing at kernel privilege, i.e. potential control-flow hijack on the host MCU, in addition to out-of-bounds reads and crashes. The attack vector is physical/local hardware access only; there is no network, USB, or syscall path to the defect. The fix clamps the reported count with min() against CONFIG_INPUT_GT911_MAX_TOUCH_POINTS before any array indexing.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-12
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zephyrproject zephyr 4.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a stack out-of-bounds write in the Goodix GT911 touch controller driver for Zephyr RTOS. The driver reads a touch point count from the device's status register without proper validation, allowing values up to 15. This count is used as a loop bound to fill a stack array sized for 1 to 5 touch points. If the device reports more points than the array can hold, up to 112 bytes of attacker-controlled data can overwrite the stack frame of the gt911_process() function, leading to potential control-flow hijacking at kernel privilege.

Detection Guidance

This vulnerability requires physical or local hardware access to exploit and cannot be detected remotely. Check if your system uses the Goodix GT911 touch controller driver in Zephyr RTOS versions 4.0.0 to 4.4.2. Inspect the driver code for unvalidated touch point counts in drivers/input/input_gt911.c. No network commands can detect this issue.

Impact Analysis

The impact includes potential control-flow hijacking at kernel privilege, out-of-bounds reads, and system crashes. The attack requires physical or local hardware access, as there is no network, USB, or syscall path to exploit the flaw. Triggering it involves substituting the I2C touch controller with a spoofed device or using a panel that ignores touch-count programming.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves a low-level kernel stack overflow in a specific hardware driver (Goodix GT911) within Zephyr RTOS. Compliance impacts would only occur if this flaw enabled unauthorized data access, modification, or system compromise on devices handling sensitive data, which is not described in the provided context.

Mitigation Strategies

Apply the patch from Zephyr RTOS version 4.5.0 or later. Update the driver to clamp the touch point count using min() against CONFIG_INPUT_GT911_MAX_TOUCH_POINTS before array indexing. Avoid using spoofable or untrusted touch controllers. Monitor for crashes in the gt911_process() function.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19576. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart