{"api_version":"1","generated_at":"2026-09-15T09:29:02+00:00","cve":"CVE-2026-80568","urls":{"html":"https://cve.report/CVE-2026-80568","api":"https://cve.report/api/cve/CVE-2026-80568.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-80568","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-80568"},"summary":{"title":"Input: synaptics-rmi4 - block s_input when F54 queue is busy","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - block s_input when F54 queue is busy\n\nChanging the input (diagnostic report type) mid-stream changes the\nreport size. Since V4L2 buffers are allocated based on the size at\nstream start, changing the input while streaming could lead to a\nheap buffer overflow if the new size is larger than the allocated\nbuffers.\n\nPrevent this by blocking VIDIOC_S_INPUT with -EBUSY if the V4L2 queue\nis busy (streaming).","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-26 15:17:12","updated_at":"2026-08-27 06:17:41"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/fa69f93015becf3729716de2199b58540aa99672","name":"https://git.kernel.org/stable/c/fa69f93015becf3729716de2199b58540aa99672","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ff0849705d29277fd1f6fc6596674b9308724fb2","name":"https://git.kernel.org/stable/c/ff0849705d29277fd1f6fc6596674b9308724fb2","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/493ba8e794729649689438edba72337111303cc4","name":"https://git.kernel.org/stable/c/493ba8e794729649689438edba72337111303cc4","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/cae79513f9115c350561b16f36adcb47c9bfff12","name":"https://git.kernel.org/stable/c/cae79513f9115c350561b16f36adcb47c9bfff12","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/1d718f1461766e9f00a8dbeb4f13f1b1c19d90ac","name":"https://git.kernel.org/stable/c/1d718f1461766e9f00a8dbeb4f13f1b1c19d90ac","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/ddd9a53faf3b65e5920cb802cb1db6f4615bdfef","name":"https://git.kernel.org/stable/c/ddd9a53faf3b65e5920cb802cb1db6f4615bdfef","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/7e994a9ecc0b49ad2fe63da9c92a8aca8a6614af","name":"https://git.kernel.org/stable/c/7e994a9ecc0b49ad2fe63da9c92a8aca8a6614af","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/fbfd76746adc16d64be29ff113f673b70bc3f5c2","name":"https://git.kernel.org/stable/c/fbfd76746adc16d64be29ff113f673b70bc3f5c2","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80568","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80568","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d 7e994a9ecc0b49ad2fe63da9c92a8aca8a6614af git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d fa69f93015becf3729716de2199b58540aa99672 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d 493ba8e794729649689438edba72337111303cc4 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d 1d718f1461766e9f00a8dbeb4f13f1b1c19d90ac git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d cae79513f9115c350561b16f36adcb47c9bfff12 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d ff0849705d29277fd1f6fc6596674b9308724fb2 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d ddd9a53faf3b65e5920cb802cb1db6f4615bdfef git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d fbfd76746adc16d64be29ff113f673b70bc3f5c2 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.9","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.9 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.266 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.217 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.184 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.153 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.105 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.46 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.10 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"80568","cve":"CVE-2026-80568","epss":"0.001330000","percentile":"0.031090000","score_date":"2026-08-27","updated_at":"2026-08-28 00:03:39"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/input/rmi4/rmi_f54.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"7e994a9ecc0b49ad2fe63da9c92a8aca8a6614af","status":"affected","version":"3a762dbd5347514c3cb2ac756a92a3d1c7646a2d","versionType":"git"},{"lessThan":"fa69f93015becf3729716de2199b58540aa99672","status":"affected","version":"3a762dbd5347514c3cb2ac756a92a3d1c7646a2d","versionType":"git"},{"lessThan":"493ba8e794729649689438edba72337111303cc4","status":"affected","version":"3a762dbd5347514c3cb2ac756a92a3d1c7646a2d","versionType":"git"},{"lessThan":"1d718f1461766e9f00a8dbeb4f13f1b1c19d90ac","status":"affected","version":"3a762dbd5347514c3cb2ac756a92a3d1c7646a2d","versionType":"git"},{"lessThan":"cae79513f9115c350561b16f36adcb47c9bfff12","status":"affected","version":"3a762dbd5347514c3cb2ac756a92a3d1c7646a2d","versionType":"git"},{"lessThan":"ff0849705d29277fd1f6fc6596674b9308724fb2","status":"affected","version":"3a762dbd5347514c3cb2ac756a92a3d1c7646a2d","versionType":"git"},{"lessThan":"ddd9a53faf3b65e5920cb802cb1db6f4615bdfef","status":"affected","version":"3a762dbd5347514c3cb2ac756a92a3d1c7646a2d","versionType":"git"},{"lessThan":"fbfd76746adc16d64be29ff113f673b70bc3f5c2","status":"affected","version":"3a762dbd5347514c3cb2ac756a92a3d1c7646a2d","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/input/rmi4/rmi_f54.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.9"},{"lessThan":"4.9","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.266","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.217","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.184","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.153","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.105","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.46","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.10","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.266","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.217","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.184","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.153","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.105","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.46","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.10","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"4.9","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - block s_input when F54 queue is busy\n\nChanging the input (diagnostic report type) mid-stream changes the\nreport size. Since V4L2 buffers are allocated based on the size at\nstream start, changing the input while streaming could lead to a\nheap buffer overflow if the new size is larger than the allocated\nbuffers.\n\nPrevent this by blocking VIDIOC_S_INPUT with -EBUSY if the V4L2 queue\nis busy (streaming)."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - Exploitation requires issuing V4L2 ioctls (VIDIOC_S_INPUT, VIDIOC_STREAMON, VIDIOC_QBUF) on the /dev/v4l-touch* node created by the synaptics-rmi4 F54 diagnostics driver; reachable only from a local process with permission to open that character device, not over the network.\nAC:L - An attacker can deterministically start streaming with a smaller F54 report type, switch to a larger type via VIDIOC_S_INPUT while the vb2 queue is busy, then queue buffers to trigger the overflow; no winning of uncontrollable races or rare layout-dependent conditions is required.\nPR:L - The vulnerable path has no capability checks beyond standard DAC on /dev/v4l-touch*; on typical laptop/kiosk/Android deployments any unprivileged local user or app granted access to the V4L2 touch diagnostics node (commonly via the video group) can invoke the bug without real root in the init namespace.\nUI:N - No victim interaction is required beyond the attacker opening the device and issuing ioctl sequences; exploitation does not depend on another user plugging hardware, mounting filesystems, or performing GUI actions.\nS:U - The flaw corrupts kernel heap memory within the same host via vb2 vmalloc buffers in the F54 V4L2 driver; impact stays in the kernel security authority and does not by itself cross VM, IOMMU, or sandbox boundaries.\nC:H - Changing the diagnostic input mid-stream makes rmi_f54_buffer_queue() memcpy() up to twice the originally allocated report size into undersized vmalloc-backed V4L2 buffers, a kernel heap out-of-bounds write that can expose or corrupt adjacent kernel memory.\nI:H - The oversized memcpy is a controlled kernel heap buffer overflow in rmi_f54_buffer_queue() that can corrupt adjacent vmalloc objects and be developed into arbitrary memory write or code-execution primitives, not merely a bounded data change.\nA:H - Writing far beyond the allocated V4L2 capture buffer can corrupt critical kernel heap metadata or adjacent structures, causing kernel oops/panic or denial of service on affected laptops, kiosks, and embedded touch systems even without full exploit development."}]}],"providerMetadata":{"dateUpdated":"2026-08-27T05:01:52.050Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/7e994a9ecc0b49ad2fe63da9c92a8aca8a6614af"},{"url":"https://git.kernel.org/stable/c/fa69f93015becf3729716de2199b58540aa99672"},{"url":"https://git.kernel.org/stable/c/493ba8e794729649689438edba72337111303cc4"},{"url":"https://git.kernel.org/stable/c/1d718f1461766e9f00a8dbeb4f13f1b1c19d90ac"},{"url":"https://git.kernel.org/stable/c/cae79513f9115c350561b16f36adcb47c9bfff12"},{"url":"https://git.kernel.org/stable/c/ff0849705d29277fd1f6fc6596674b9308724fb2"},{"url":"https://git.kernel.org/stable/c/ddd9a53faf3b65e5920cb802cb1db6f4615bdfef"},{"url":"https://git.kernel.org/stable/c/fbfd76746adc16d64be29ff113f673b70bc3f5c2"}],"title":"Input: synaptics-rmi4 - block s_input when F54 queue is busy","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-80568","datePublished":"2026-08-26T14:37:30.740Z","dateReserved":"2026-08-26T14:34:25.768Z","dateUpdated":"2026-08-27T05:01:52.050Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-26 15:17:12","lastModifiedDate":"2026-08-27 06:17:41","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"80568","Ordinal":"1","Title":"Input: synaptics-rmi4 - block s_input when F54 queue is busy","CVE":"CVE-2026-80568","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"80568","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - block s_input when F54 queue is busy\n\nChanging the input (diagnostic report type) mid-stream changes the\nreport size. Since V4L2 buffers are allocated based on the size at\nstream start, changing the input while streaming could lead to a\nheap buffer overflow if the new size is larger than the allocated\nbuffers.\n\nPrevent this by blocking VIDIOC_S_INPUT with -EBUSY if the V4L2 queue\nis busy (streaming).","Type":"Description","Title":"Input: synaptics-rmi4 - block s_input when F54 queue is busy"}]}}}