CVE-2026-98206
Received
Received - Intake
Buffer Overflow in Linux Kernel cyttsp5 Driver
Vulnerability report for CVE-2026-98206, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
Input: cyttsp5 - clamp the HID report size before memcpy
The size field comes from the device and is used as the memcpy()
length into response_buf, which is CY_MAX_INPUT bytes.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 5b0c03e24a061f9c9e8b28fa157b80990c559a37 |
| Linux | Linux | 5b0c03e24a061f9c9e8b28fa157b80990c559a37 |
| Linux | Linux | 5b0c03e24a061f9c9e8b28fa157b80990c559a37 |
| Linux | Linux | 5b0c03e24a061f9c9e8b28fa157b80990c559a37 |
| Linux | Linux | 5b0c03e24a061f9c9e8b28fa157b80990c559a37 |
| Linux | Linux | 6.2 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |