CVE-2026-64276 Details
Description
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count rmi_f30_map_gpios() allocates gpioled_key_map with min(gpioled_count, TRACKSTICK_RANGE_END) == at most 6 entries, but rmi_f30_attention() iterates the full f30->gpioled_count (device query register, range 0..31) and dereferences gpioled_key_map[i], and input->keycodemax is set to the full gpioled_count while input->keycode points at the 6-entry allocation. A device that reports gpioled_count > 6 with GPIO support enabled therefore causes an out-of-bounds read on the attention interrupt and out-of-bounds read/write through the EVIOCGKEYCODE/EVIOCSKEYCODE ioctls, which bound the index only against keycodemax. This is the same defect as the F3A handler, which was copied from F30. Size the keymap for the full gpioled_count; the mapping loop still assigns only the first min(gpioled_count, TRACKSTICK_RANGE_END) entries.
A vulnerability in the Linux kernel's handling of the synaptics RMI4 F30 keymap can lead to out-of-bounds read and write operations. The issue arises because the F30 keymap's GPIO/LED count is not properly managed, allowing devices to report a higher count than the allocated keymap can handle. This discrepancy causes an out-of-bounds read on the attention interrupt and unauthorized read/write operations through specific ioctls, similar to a previously identified defect in the F3A handler.
The vulnerability has been addressed in the Linux kernel. Users should upgrade to the latest version where this issue has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/26c895928d7118436a24f564587cb4aefc40cdd8 | kernel.org | Patch |
| https://git.kernel.org/stable/c/4e3689c26854356f41fbaa1eafa382e58ac79e00 | kernel.org | Patch |
| https://git.kernel.org/stable/c/8c6d18d61bb6fe0e6edf848413391c590552e8a9 | kernel.org | Patch |
| https://git.kernel.org/stable/c/bfe622efecd4ff0a792d0ecd1a8dce535a902f50 | kernel.org | Patch |
| https://git.kernel.org/stable/c/d162a1ead7de404d8b41a093c83ed0db6487cded | kernel.org | Patch |
| https://git.kernel.org/stable/c/d577e46785d45484b2ab7e7309c49b18764bf56c | kernel.org | Patch |
| https://git.kernel.org/stable/c/e849c6f51e6877104c765da084e001ec37c8e119 | kernel.org | Patch |
| https://git.kernel.org/stable/c/f0be9eba946e9200b43265e0a748d38bd0a56954 | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-787 | Out-of-bounds Write | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 4.14.1, < 5.10.261 >= 5.11, < 5.15.212 >= 5.16, < 6.1.178 >= 6.2, < 6.6.145 >= 6.7, < 6.12.96 >= 6.13, < 6.18.39 >= 6.19, < 7.1.4 4.14 - 4.14 rc7 4.14 rc8 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 17, 2026 | CVE Modified | kernel.org |
| Aug 13, 2026 | Initial Analysis | [email protected] |
| Jul 27, 2026 | CVE Modified | kernel.org |
| Jul 25, 2026 | New CVE Received | kernel.org |