Input: synaptics-rmi4 - fix F55 transmitter electrode count typo
Summary
| CVE | CVE-2026-80754 |
|---|---|
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-09-03 13:06:15 UTC |
| Updated | 2026-09-04 05:17:15 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - fix F55 transmitter electrode count typo During F55 sensor detection, the transmitter (TX) electrode count was incorrectly assigned the value of the receiver (RX) electrode count due to copy-paste typos. This incorrect value was then propagated to the driver data and used by F54 to determine the diagnostics report size. On devices with more RX than TX electrodes, this inflated the perceived TX count, leading to incorrect report size calculations and potential out-of-bounds buffer accesses. Fix the typos by correctly assigning the TX electrode counts. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from 416baaa9-dc9f-4396-8d5f-8c081fb06d67
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.001640000 probability, percentile 0.058780000 (date 2026-09-07)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Linux | Linux | affected 6adba43fd222ea362c36296d1a6897c2e28fdc8e 6484e00d6778fdf2209cd75940bc3902b276457f git | Not specified |
| CNA | Linux | Linux | affected 6adba43fd222ea362c36296d1a6897c2e28fdc8e db4e20265ebda729610ca5cf45ca9437462c3f36 git | Not specified |
| CNA | Linux | Linux | affected 6adba43fd222ea362c36296d1a6897c2e28fdc8e a6d9646e77da7cab2dff7043a8e9f75e23b836bc git | Not specified |
| CNA | Linux | Linux | affected 6adba43fd222ea362c36296d1a6897c2e28fdc8e 0739c65e799d4a93fe573ed23255a71fcfcc5438 git | Not specified |
| CNA | Linux | Linux | affected 6adba43fd222ea362c36296d1a6897c2e28fdc8e 9759502f5cd71805923457f183ae5b9533e20c7b git | Not specified |
| CNA | Linux | Linux | affected 6adba43fd222ea362c36296d1a6897c2e28fdc8e 9b184c8337c6e12df129399007735a7fbcbbcb7b git | Not specified |
| CNA | Linux | Linux | affected 6adba43fd222ea362c36296d1a6897c2e28fdc8e a81cafe3c3c2f8494063385a7b0ea7ff407bf19f git | Not specified |
| CNA | Linux | Linux | affected 6adba43fd222ea362c36296d1a6897c2e28fdc8e 6058f0fea10f3caf63a435677358d1b8e9325114 git | Not specified |
| CNA | Linux | Linux | affected 4.10 | Not specified |
| CNA | Linux | Linux | unaffected 4.10 semver | Not specified |
| CNA | Linux | Linux | unaffected 5.10.266 5.10.* semver | Not specified |
| CNA | Linux | Linux | unaffected 5.15.217 5.15.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.1.184 6.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.6.153 6.6.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.12.105 6.12.* semver | Not specified |
| CNA | Linux | Linux | unaffected 6.18.46 6.18.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.1.10 7.1.* semver | Not specified |
| CNA | Linux | Linux | unaffected 7.2 * original_commit_for_fix | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| git.kernel.org/stable/c/a6d9646e77da7cab2dff7043a8e9f75e23b836bc | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/9b184c8337c6e12df129399007735a7fbcbbcb7b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/a81cafe3c3c2f8494063385a7b0ea7ff407bf19f | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/0739c65e799d4a93fe573ed23255a71fcfcc5438 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/6058f0fea10f3caf63a435677358d1b8e9325114 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/db4e20265ebda729610ca5cf45ca9437462c3f36 | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/9759502f5cd71805923457f183ae5b9533e20c7b | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| git.kernel.org/stable/c/6484e00d6778fdf2209cd75940bc3902b276457f | 416baaa9-dc9f-4396-8d5f-8c081fb06d67 | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.