๐Ÿ” CVE Alert

CVE-2026-64277

UNKNOWN 0.0

Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count rmi_f3a_initialize() takes the GPIO count from the device query register (f3a->gpio_count = buf & RMI_F3A_GPIO_COUNT, range 0..127). rmi_f3a_map_gpios() then allocates gpio_key_map with min(gpio_count, TRACKSTICK_RANGE_END) == at most 6 entries, but rmi_f3a_attention() iterates the full gpio_count and dereferences gpio_key_map[i], and input->keycodemax is set to the full gpio_count while input->keycode points at the 6-entry allocation. A device that reports gpio_count > 6 therefore causes an out-of-bounds read of gpio_key_map[] on every attention interrupt, and out-of-bounds accesses through the input core's default keymap ioctls: EVIOCGKEYCODE reads past the buffer (leaking adjacent slab memory to user space) and EVIOCSKEYCODE writes a caller-controlled value past it, for any process able to open the evdev node, since input_default_getkeycode() and input_default_setkeycode() only bound the index against keycodemax. Size the keymap for the full gpio_count. The mapping loop is unchanged: it still assigns only the first min(gpio_count, TRACKSTICK_RANGE_END) entries; the remaining slots stay KEY_RESERVED (devm_kcalloc zero-fills) and are skipped when reporting.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Jul 25, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
9e4c596bfd004f447a652205163234dfd4aafa69 < 502ad7caaa1a445b734c827fa256e5311df67e3d 9e4c596bfd004f447a652205163234dfd4aafa69 < 3480e24bc4e178aaa009edb25b6ee12df199e210 9e4c596bfd004f447a652205163234dfd4aafa69 < 35ed74d32d8260bdfb14a94caf402bf0866bdeec 9e4c596bfd004f447a652205163234dfd4aafa69 < ba57f430328534501962d60d651e385ffd7af9ca 9e4c596bfd004f447a652205163234dfd4aafa69 < 850117b637bcb1dcc14be0cf09ac819a8707b42c 9e4c596bfd004f447a652205163234dfd4aafa69 < 8db211aed83733073b0814adaeeab61d4521474e 9e4c596bfd004f447a652205163234dfd4aafa69 < 64fb0e1161ccc6b9e48b8df61f07d3c34c01ec42 9e4c596bfd004f447a652205163234dfd4aafa69 < 57c10915f2c16c90e0d46ad00876bf39ece40fc2
Linux / Linux
5.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/502ad7caaa1a445b734c827fa256e5311df67e3d git.kernel.org: https://git.kernel.org/stable/c/3480e24bc4e178aaa009edb25b6ee12df199e210 git.kernel.org: https://git.kernel.org/stable/c/35ed74d32d8260bdfb14a94caf402bf0866bdeec git.kernel.org: https://git.kernel.org/stable/c/ba57f430328534501962d60d651e385ffd7af9ca git.kernel.org: https://git.kernel.org/stable/c/850117b637bcb1dcc14be0cf09ac819a8707b42c git.kernel.org: https://git.kernel.org/stable/c/8db211aed83733073b0814adaeeab61d4521474e git.kernel.org: https://git.kernel.org/stable/c/64fb0e1161ccc6b9e48b8df61f07d3c34c01ec42 git.kernel.org: https://git.kernel.org/stable/c/57c10915f2c16c90e0d46ad00876bf39ece40fc2