Review reviewHigh

CVE-2026-64364

Linux

In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: fix out-of-bounds bit access on mt_io_flags mt_io_flags is a single unsigned long, but mt_process_slot(), mt_release_pending_palms() and mt_release_contacts() use it as a per-slot bitmap indexed by the slot number. That slot number is only bounded by td->maxcontacts, which is taken from the device's ContactCountMaximum feature report and can be up to 255, not by BITS_PER_LONG. As a result, a multitouch device that advertises a large contact count makes set_bit()/clear_bit() operate past the mt_io_flags word...

CVSS
8.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.07.25
PRIORITY ASSESSMENT

Review review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 8.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: fix out-of-bounds bit access on mt_io_flags mt_io_flags is a single unsigned long, but mt_process_slot(), mt_release_pending_palms() and mt_release_contacts() use it as a per-slot bitmap indexed by the slot number. That slot number is only bounded by td->maxcontacts, which is taken from the device's ContactCountMaximum feature report and can be up to 255, not by BITS_PER_LONG. As a result, a multitouch device that advertises a large contact count makes set_bit()/clear_bit() operate past the mt_io_flags word...

Affected product and versions

Product
Linux
Affected versions
>= fc488f675344931ffab6a51c43691065ec006567 < 12e90656e330ff8bbaf2f29c535fdb8a11cc6f55, >= 77711d850bed75ae7142c3d1f22c1a8b4d049c33 < 152983d87387f6a8ae72b73474cfa55fbcf1ec75, >= 6acfe25968913788d30ec0eedd80178c4ea3f1d0 < b5c037d6b807017e74a115288f81bc9cd5a5aab8, >= d280c138e66be87d1fccfed42593f02fdb893905 < a6d5ce2e1a2d7bf189bde8a659d04b65f0b0725d, >= f32fea4c0234c971c12e46d76612cdc2dd4bb046 < e24918ee67c4dc3d20d4670750e46e9b160365f4, >= 46f781e0d151844589dc2125c8cce3300546f92a < 37daa8c96bd563d03150e23f094cb60703594a6d, >= 46f781e0d151844589dc2125c8cce3300546f92a < 6493ebf9489efef0105078377b973ab33d51af22, >= 46f781e0d151844589dc2125c8cce3300546f92a < 8813b0612275cc61fe9e6603d0ee019247ade6be, >= 59bd04163e6451b9c7275277882ed9f4abfa2051, >= 5.10.246 < 5.10.261, >= 5.15.196 < 5.15.212, >= 6.1.158 < 6.1.178, >= 6.6.114 < 6.6.145, >= 6.12.55 < 6.12.97, >= 6.17.5 < 6.18, >= 6.18
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
Not available
CVE-2026-64364 — Linux | SECUFOCUS NOW