{"api_version":"1","generated_at":"2026-09-15T09:29:02+00:00","cve":"CVE-2026-80570","urls":{"html":"https://cve.report/CVE-2026-80570","api":"https://cve.report/api/cve/CVE-2026-80570.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-80570","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-80570"},"summary":{"title":"Input: synaptics-rmi4 - zero report size on F54 work error","description":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - zero report size on F54 work error\n\nIn rmi_f54_work(), if an error occurs during report request or command\nverification, the code jumped directly to the 'error' label, bypassing\nthe 'abort' label where f54->report_size was normally zeroed out.\n\nThis left f54->report_size containing its previous successful payload\nsize. If a user then altered the V4L2 format to a smaller size, and a\nsubsequent run failed, rmi_f54_buffer_queue() would copy the stale,\nlarger payload size into the shrunken V4L2 buffer, causing a heap\nbuffer overflow.\n\nFix this by merging the 'abort' and 'error' labels into a single 'out'\nexit path, and ensuring that f54->report_size is always set to 0 on\nfailure by checking for error and zeroing the local report_size first.","state":"PUBLISHED","assigner":"Linux","published_at":"2026-08-26 15:17:12","updated_at":"2026-08-27 06:17:42"},"problem_types":[],"metrics":[{"version":"3.1","source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"}},{"version":"3.1","source":"CNA","type":"DECLARED","score":"7.8","severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","data":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"}}],"references":[{"url":"https://git.kernel.org/stable/c/79521ed3cc9ea48476666ccacf45ecd6954b29a4","name":"https://git.kernel.org/stable/c/79521ed3cc9ea48476666ccacf45ecd6954b29a4","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/c6cfda79f26c69e97db9805808c3b44d02227b4b","name":"https://git.kernel.org/stable/c/c6cfda79f26c69e97db9805808c3b44d02227b4b","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/77749685e55da19b187df215b5da4080842ca5c7","name":"https://git.kernel.org/stable/c/77749685e55da19b187df215b5da4080842ca5c7","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/88c8174d72900d77fbdf2f527d54b6ff2da876a8","name":"https://git.kernel.org/stable/c/88c8174d72900d77fbdf2f527d54b6ff2da876a8","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/dc76c3c8e8ad09362b8c1561f3928288c15cba2e","name":"https://git.kernel.org/stable/c/dc76c3c8e8ad09362b8c1561f3928288c15cba2e","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/62079c17ec07d64362bec367ee7a525b0dbf6bf9","name":"https://git.kernel.org/stable/c/62079c17ec07d64362bec367ee7a525b0dbf6bf9","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/b28593a05afdd812b590e1045b5bd862a5869225","name":"https://git.kernel.org/stable/c/b28593a05afdd812b590e1045b5bd862a5869225","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://git.kernel.org/stable/c/c669c64ab71afa7b467c4d7e18f6a05e96b97a1f","name":"https://git.kernel.org/stable/c/c669c64ab71afa7b467c4d7e18f6a05e96b97a1f","refsource":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-80570","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80570","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d 62079c17ec07d64362bec367ee7a525b0dbf6bf9 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d 79521ed3cc9ea48476666ccacf45ecd6954b29a4 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d c669c64ab71afa7b467c4d7e18f6a05e96b97a1f git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d 77749685e55da19b187df215b5da4080842ca5c7 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d c6cfda79f26c69e97db9805808c3b44d02227b4b git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d b28593a05afdd812b590e1045b5bd862a5869225 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d 88c8174d72900d77fbdf2f527d54b6ff2da876a8 git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d dc76c3c8e8ad09362b8c1561f3928288c15cba2e git","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"affected 4.9","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 4.9 semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.10.266 5.10.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 5.15.217 5.15.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.1.184 6.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.6.153 6.6.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.12.105 6.12.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 6.18.46 6.18.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.1.10 7.1.* semver","platforms":[]},{"source":"CNA","vendor":"Linux","product":"Linux","version":"unaffected 7.2 * original_commit_for_fix","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"80570","cve":"CVE-2026-80570","epss":"0.001340000","percentile":"0.032240000","score_date":"2026-08-27","updated_at":"2026-08-28 00:03:39"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Linux","programFiles":["drivers/input/rmi4/rmi_f54.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"lessThan":"62079c17ec07d64362bec367ee7a525b0dbf6bf9","status":"affected","version":"3a762dbd5347514c3cb2ac756a92a3d1c7646a2d","versionType":"git"},{"lessThan":"79521ed3cc9ea48476666ccacf45ecd6954b29a4","status":"affected","version":"3a762dbd5347514c3cb2ac756a92a3d1c7646a2d","versionType":"git"},{"lessThan":"c669c64ab71afa7b467c4d7e18f6a05e96b97a1f","status":"affected","version":"3a762dbd5347514c3cb2ac756a92a3d1c7646a2d","versionType":"git"},{"lessThan":"77749685e55da19b187df215b5da4080842ca5c7","status":"affected","version":"3a762dbd5347514c3cb2ac756a92a3d1c7646a2d","versionType":"git"},{"lessThan":"c6cfda79f26c69e97db9805808c3b44d02227b4b","status":"affected","version":"3a762dbd5347514c3cb2ac756a92a3d1c7646a2d","versionType":"git"},{"lessThan":"b28593a05afdd812b590e1045b5bd862a5869225","status":"affected","version":"3a762dbd5347514c3cb2ac756a92a3d1c7646a2d","versionType":"git"},{"lessThan":"88c8174d72900d77fbdf2f527d54b6ff2da876a8","status":"affected","version":"3a762dbd5347514c3cb2ac756a92a3d1c7646a2d","versionType":"git"},{"lessThan":"dc76c3c8e8ad09362b8c1561f3928288c15cba2e","status":"affected","version":"3a762dbd5347514c3cb2ac756a92a3d1c7646a2d","versionType":"git"}]},{"defaultStatus":"affected","product":"Linux","programFiles":["drivers/input/rmi4/rmi_f54.c"],"repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","vendor":"Linux","versions":[{"status":"affected","version":"4.9"},{"lessThan":"4.9","status":"unaffected","version":"0","versionType":"semver"},{"lessThanOrEqual":"5.10.*","status":"unaffected","version":"5.10.266","versionType":"semver"},{"lessThanOrEqual":"5.15.*","status":"unaffected","version":"5.15.217","versionType":"semver"},{"lessThanOrEqual":"6.1.*","status":"unaffected","version":"6.1.184","versionType":"semver"},{"lessThanOrEqual":"6.6.*","status":"unaffected","version":"6.6.153","versionType":"semver"},{"lessThanOrEqual":"6.12.*","status":"unaffected","version":"6.12.105","versionType":"semver"},{"lessThanOrEqual":"6.18.*","status":"unaffected","version":"6.18.46","versionType":"semver"},{"lessThanOrEqual":"7.1.*","status":"unaffected","version":"7.1.10","versionType":"semver"},{"lessThanOrEqual":"*","status":"unaffected","version":"7.2","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.10.266","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"5.15.217","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.1.184","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.6.153","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.12.105","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"6.18.46","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.1.10","versionStartIncluding":"4.9","vulnerable":true},{"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"7.2","versionStartIncluding":"4.9","vulnerable":true}],"negate":false,"operator":"OR"}]}],"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - zero report size on F54 work error\n\nIn rmi_f54_work(), if an error occurs during report request or command\nverification, the code jumped directly to the 'error' label, bypassing\nthe 'abort' label where f54->report_size was normally zeroed out.\n\nThis left f54->report_size containing its previous successful payload\nsize. If a user then altered the V4L2 format to a smaller size, and a\nsubsequent run failed, rmi_f54_buffer_queue() would copy the stale,\nlarger payload size into the shrunken V4L2 buffer, causing a heap\nbuffer overflow.\n\nFix this by merging the 'abort' and 'error' labels into a single 'out'\nexit path, and ensuring that f54->report_size is always set to 0 on\nfailure by checking for error and zeroing the local report_size first."}],"metrics":[{"cvssV3_1":{"baseScore":7.8,"baseSeverity":"HIGH","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"scenarios":[{"lang":"en","value":"AV:L - Exploitation requires local V4L2 ioctls on the synaptics-rmi4 F54 diagnostics node (/dev/v4l-touch*); open/STREAMON/QBUF drives rmi_f54_buffer_queue() memcpy() using stale f54->report_size. There is no network, Bluetooth, or physical-bus injection path to this code.\nAC:L - An attacker can capture a large F54 report, stop streaming, switch VIDIOC_S_INPUT to a smaller report type, then re-stream and retry until rmi_f54_work() takes the error goto (timeout or register-read failure); ioctl timing is attacker-controlled and no uncontrollable victim state is required.\nPR:L - Triggering the overflow needs only permission to open the registered VFL_TYPE_TOUCH device and issue standard V4L2 capture ioctls; on typical laptop, kiosk, and Android deployments this is granted to unprivileged local users via video/input device policy without init-namespace root.\nUI:N - No cooperative victim action is required; the attacker opens the diagnostics node, performs the capture/input-change/re-stream sequence, and queues buffers themselves. No other user must mount filesystems, plug devices, or perform GUI actions at exploit time.\nS:U - The flaw corrupts kernel heap memory via vb2 vmalloc buffers in the F54 V4L2 driver on the same host; impact stays within the kernel security authority and does not by itself cross VM, IOMMU, or sandbox boundaries.\nC:H - On worker failure f54->report_size retains the prior successful payload size, so memcpy() can write up to roughly twice the newly allocated V4L2 buffer into adjacent vmalloc heap memory, enabling disclosure or corruption of neighboring kernel objects.\nI:H - The stale-size memcpy in rmi_f54_buffer_queue() is a controlled kernel heap buffer overflow that can corrupt adjacent vmalloc objects and be developed into arbitrary memory write or code-execution primitives, not merely a bounded data change.\nA:H - Writing far beyond the shrunken V4L2 capture buffer can corrupt critical kernel heap metadata or adjacent structures, causing kernel oops or panic on affected laptops, kiosks, and embedded touch systems even without full exploit development."}]}],"providerMetadata":{"dateUpdated":"2026-08-27T05:01:54.209Z","orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux"},"references":[{"url":"https://git.kernel.org/stable/c/62079c17ec07d64362bec367ee7a525b0dbf6bf9"},{"url":"https://git.kernel.org/stable/c/79521ed3cc9ea48476666ccacf45ecd6954b29a4"},{"url":"https://git.kernel.org/stable/c/c669c64ab71afa7b467c4d7e18f6a05e96b97a1f"},{"url":"https://git.kernel.org/stable/c/77749685e55da19b187df215b5da4080842ca5c7"},{"url":"https://git.kernel.org/stable/c/c6cfda79f26c69e97db9805808c3b44d02227b4b"},{"url":"https://git.kernel.org/stable/c/b28593a05afdd812b590e1045b5bd862a5869225"},{"url":"https://git.kernel.org/stable/c/88c8174d72900d77fbdf2f527d54b6ff2da876a8"},{"url":"https://git.kernel.org/stable/c/dc76c3c8e8ad09362b8c1561f3928288c15cba2e"}],"title":"Input: synaptics-rmi4 - zero report size on F54 work error","x_generator":{"engine":"bippy-1.2.0"}}},"cveMetadata":{"assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","assignerShortName":"Linux","cveId":"CVE-2026-80570","datePublished":"2026-08-26T14:37:31.940Z","dateReserved":"2026-08-26T14:34:25.768Z","dateUpdated":"2026-08-27T05:01:54.209Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-26 15:17:12","lastModifiedDate":"2026-08-27 06:17:42","problem_types":[],"metrics":{"cvssMetricV31":[{"source":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"80570","Ordinal":"1","Title":"Input: synaptics-rmi4 - zero report size on F54 work error","CVE":"CVE-2026-80570","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"80570","Ordinal":"1","NoteData":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - zero report size on F54 work error\n\nIn rmi_f54_work(), if an error occurs during report request or command\nverification, the code jumped directly to the 'error' label, bypassing\nthe 'abort' label where f54->report_size was normally zeroed out.\n\nThis left f54->report_size containing its previous successful payload\nsize. If a user then altered the V4L2 format to a smaller size, and a\nsubsequent run failed, rmi_f54_buffer_queue() would copy the stale,\nlarger payload size into the shrunken V4L2 buffer, causing a heap\nbuffer overflow.\n\nFix this by merging the 'abort' and 'error' labels into a single 'out'\nexit path, and ensuring that f54->report_size is always set to 0 on\nfailure by checking for error and zeroing the local report_size first.","Type":"Description","Title":"Input: synaptics-rmi4 - zero report size on F54 work error"}]}}}