HID: multitouch: fix out-of-bounds bit access on mt_io_flags

Summary

CVECVE-2026-64364
StatePUBLISHED
AssignerLinux
Source PriorityCVE Program / NVD first with legacy fallback
Published2026-07-25 10:17:19 UTC
Updated2026-07-27 05:16:43 UTC
DescriptionIn the Linux kernel, the following vulnerability has been resolved: HID: multitouch: fix out-of-bounds bit access on mt_io_flags mt_io_flags is a single unsigned long, but mt_process_slot(), mt_release_pending_palms() and mt_release_contacts() use it as a per-slot bitmap indexed by the slot number. That slot number is only bounded by td->maxcontacts, which is taken from the device's ContactCountMaximum feature report and can be up to 255, not by BITS_PER_LONG. As a result, a multitouch device that advertises a large contact count makes set_bit()/clear_bit() operate past the mt_io_flags word and corrupt the adjacent members of struct mt_device. The sticky-fingers release timer is the easiest way to reach this. mt_release_contacts() runs for (i = 0; i < mt->num_slots; i++) clear_bit(i, &td->mt_io_flags); with num_slots == maxcontacts. For maxcontacts around 250 the loop clears the bits that overlap td->applications.next, zeroing that list head, and the list_for_each_entry() that immediately follows then dereferences NULL. The kernel panics from timer (softirq) context. On a KASAN build this shows up as a general protection fault in mt_release_contacts() with a null-ptr-deref at offset 0x58, which is offsetof(struct mt_application, num_received). The state is reachable from an untrusted USB or Bluetooth HID multitouch device; no local privileges are required. Store the per-slot active state in a separately allocated bitmap sized for maxcontacts, the same pattern already used for pending_palm_slots, and keep only MT_IO_FLAGS_RUNNING in mt_io_flags. The two "mt_io_flags & MT_IO_SLOTS_MASK" arming checks become bitmap_empty(td->active_slots, td->maxcontacts). Move MT_IO_FLAGS_RUNNING back to bit 0. It was bumped to bit 32 by the same commit to leave the low byte for the slot bits; with the slot bits gone it fits in bit 0 again, which also keeps it within the unsigned long on 32-bit.

Risk And Classification

Primary CVSS: v3.1 8.8 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS: 0.003450000 probability, percentile 0.270010000 (date 2026-07-27)


VersionSourceTypeScoreSeverityVector
3.1416baaa9-dc9f-4396-8d5f-8c081fb06d67Secondary8.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
3.1CNADECLARED8.8HIGHCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS v3.1 Breakdown

Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Vendor Declared Affected Products

SourceVendorProductVersionPlatforms
CNA Linux Linux affected fc488f675344931ffab6a51c43691065ec006567 12e90656e330ff8bbaf2f29c535fdb8a11cc6f55 git Not specified
CNA Linux Linux affected 77711d850bed75ae7142c3d1f22c1a8b4d049c33 152983d87387f6a8ae72b73474cfa55fbcf1ec75 git Not specified
CNA Linux Linux affected 6acfe25968913788d30ec0eedd80178c4ea3f1d0 b5c037d6b807017e74a115288f81bc9cd5a5aab8 git Not specified
CNA Linux Linux affected d280c138e66be87d1fccfed42593f02fdb893905 a6d5ce2e1a2d7bf189bde8a659d04b65f0b0725d git Not specified
CNA Linux Linux affected f32fea4c0234c971c12e46d76612cdc2dd4bb046 e24918ee67c4dc3d20d4670750e46e9b160365f4 git Not specified
CNA Linux Linux affected 46f781e0d151844589dc2125c8cce3300546f92a 37daa8c96bd563d03150e23f094cb60703594a6d git Not specified
CNA Linux Linux affected 46f781e0d151844589dc2125c8cce3300546f92a 6493ebf9489efef0105078377b973ab33d51af22 git Not specified
CNA Linux Linux affected 46f781e0d151844589dc2125c8cce3300546f92a 8813b0612275cc61fe9e6603d0ee019247ade6be git Not specified
CNA Linux Linux affected 59bd04163e6451b9c7275277882ed9f4abfa2051 git Not specified
CNA Linux Linux affected 5.10.246 5.10.261 semver Not specified
CNA Linux Linux affected 5.15.196 5.15.212 semver Not specified
CNA Linux Linux affected 6.1.158 6.1.178 semver Not specified
CNA Linux Linux affected 6.6.114 6.6.145 semver Not specified
CNA Linux Linux affected 6.12.55 6.12.97 semver Not specified
CNA Linux Linux affected 6.17.5 6.18 semver Not specified
CNA Linux Linux affected 6.18 Not specified
CNA Linux Linux unaffected 6.18 semver Not specified
CNA Linux Linux unaffected 5.10.261 5.10.* semver Not specified
CNA Linux Linux unaffected 5.15.212 5.15.* semver Not specified
CNA Linux Linux unaffected 6.1.178 6.1.* semver Not specified
CNA Linux Linux unaffected 6.6.145 6.6.* semver Not specified
CNA Linux Linux unaffected 6.12.97 6.12.* semver Not specified
CNA Linux Linux unaffected 6.18.39 6.18.* semver Not specified
CNA Linux Linux unaffected 7.1.4 7.1.* semver Not specified
CNA Linux Linux unaffected 7.2-rc3 * original_commit_for_fix Not specified

References

ReferenceSourceLinkTags
git.kernel.org/stable/c/6493ebf9489efef0105078377b973ab33d51af22 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/e24918ee67c4dc3d20d4670750e46e9b160365f4 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/b5c037d6b807017e74a115288f81bc9cd5a5aab8 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/37daa8c96bd563d03150e23f094cb60703594a6d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/a6d5ce2e1a2d7bf189bde8a659d04b65f0b0725d 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/12e90656e330ff8bbaf2f29c535fdb8a11cc6f55 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/152983d87387f6a8ae72b73474cfa55fbcf1ec75 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
git.kernel.org/stable/c/8813b0612275cc61fe9e6603d0ee019247ade6be 416baaa9-dc9f-4396-8d5f-8c081fb06d67 git.kernel.org
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report