CVE-2026-64277 Details
Description
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count rmi_f3a_initialize() takes the GPIO count from the device query register (f3a->gpio_count = buf & RMI_F3A_GPIO_COUNT, range 0..127). rmi_f3a_map_gpios() then allocates gpio_key_map with min(gpio_count, TRACKSTICK_RANGE_END) == at most 6 entries, but rmi_f3a_attention() iterates the full gpio_count and dereferences gpio_key_map[i], and input->keycodemax is set to the full gpio_count while input->keycode points at the 6-entry allocation. A device that reports gpio_count > 6 therefore causes an out-of-bounds read of gpio_key_map[] on every attention interrupt, and out-of-bounds accesses through the input core's default keymap ioctls: EVIOCGKEYCODE reads past the buffer (leaking adjacent slab memory to user space) and EVIOCSKEYCODE writes a caller-controlled value past it, for any process able to open the evdev node, since input_default_getkeycode() and input_default_setkeycode() only bound the index against keycodemax. Size the keymap for the full gpio_count. The mapping loop is unchanged: it still assigns only the first min(gpio_count, TRACKSTICK_RANGE_END) entries; the remaining slots stay KEY_RESERVED (devm_kcalloc zero-fills) and are skipped when reporting.
A vulnerability in the Linux kernel's handling of GPIO counts for Synaptics RMI4 F3A keymaps can lead to out-of-bounds memory access. The issue arises in the 'rmi_f3a_map_gpios' function, where the allocated GPIO keymap does not account for devices reporting a GPIO count greater than six. This discrepancy allows for out-of-bounds reads of the keymap during attention interrupts, potentially leaking adjacent memory to user space. Furthermore, the vulnerability enables out-of-bounds writes through the input core's default keymap IOCTLs, allowing controlled values to be written past the allocated buffer.
The vulnerability has been addressed in the Linux kernel by modifying the keymap allocation to match the full GPIO count reported by the device. Users should upgrade to the latest version of the Linux kernel where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://git.kernel.org/stable/c/3480e24bc4e178aaa009edb25b6ee12df199e210 | kernel.org | Patch |
| https://git.kernel.org/stable/c/35ed74d32d8260bdfb14a94caf402bf0866bdeec | kernel.org | Patch |
| https://git.kernel.org/stable/c/502ad7caaa1a445b734c827fa256e5311df67e3d | kernel.org | Patch |
| https://git.kernel.org/stable/c/57c10915f2c16c90e0d46ad00876bf39ece40fc2 | kernel.org | Patch |
| https://git.kernel.org/stable/c/64fb0e1161ccc6b9e48b8df61f07d3c34c01ec42 | kernel.org | Patch |
| https://git.kernel.org/stable/c/850117b637bcb1dcc14be0cf09ac819a8707b42c | kernel.org | Patch |
| https://git.kernel.org/stable/c/8db211aed83733073b0814adaeeab61d4521474e | kernel.org | Patch |
| https://git.kernel.org/stable/c/ba57f430328534501962d60d651e385ffd7af9ca | kernel.org | Patch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-125 | Out-of-bounds Read | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| linux linux kernel | >= 5.10, < 5.10.261 >= 5.11, < 5.15.212 >= 5.16, < 6.1.178 >= 6.2, < 6.6.145 >= 6.7, < 6.12.96 >= 6.13, < 6.18.39 >= 6.19, < 7.1.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 17, 2026 | CVE Modified | kernel.org |
| Aug 13, 2026 | Initial Analysis | [email protected] |
| Jul 27, 2026 | CVE Modified | kernel.org |
| Jul 25, 2026 | New CVE Received | kernel.org |