ReviewHigh

CVE-2026-80569

Linux

In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer rmi_f54_work() reads a diagnostics report from the device into f54->report_data, sizing the transfer with rmi_f54_get_report_size(): report_size = rmi_f54_get_report_size(f54); ... for (i = 0; i < report_size; i += F54_REPORT_DATA_SIZE) { int size = min(F54_REPORT_DATA_SIZE, report_size - i); ... rmi_read_block(.., f54->report_data + i, size); } report_data is allocated once at probe from F54's own electrode counts (array3_size(f54->num_tx_electrodes,...

CVSS
7.8
EPSS
-
- percentile
CISA KEV
Not listed
Published
2026.08.27
PRIORITY ASSESSMENT

Review

The CVSS severity warrants an early asset and exposure review.

Known exploitationNot established by KEV
Exploit probability-
Technical severityCVSS 7.8

Vulnerability overview

In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer rmi_f54_work() reads a diagnostics report from the device into f54->report_data, sizing the transfer with rmi_f54_get_report_size(): report_size = rmi_f54_get_report_size(f54); ... for (i = 0; i < report_size; i += F54_REPORT_DATA_SIZE) { int size = min(F54_REPORT_DATA_SIZE, report_size - i); ... rmi_read_block(.., f54->report_data + i, size); } report_data is allocated once at probe from F54's own electrode counts (array3_size(f54->num_tx_electrodes,...

Affected product and versions

Product
Linux
Affected versions
>= c762cc68b6a12eedebefc156ea4838e54804e2eb < 6b3bdd44d4cd7d5e35de1d0f06d4930f3cecd403, >= c762cc68b6a12eedebefc156ea4838e54804e2eb < b2f596f00d27703ce09167201ba57f55be8d2f9a, >= c762cc68b6a12eedebefc156ea4838e54804e2eb < b3932101c9c457148038392bc977f9b31e125a86, >= c762cc68b6a12eedebefc156ea4838e54804e2eb < 12be3c6ca9589afd6ade41a59c761866e526634d, >= c762cc68b6a12eedebefc156ea4838e54804e2eb < 42eaf0e6f79c487f419737314cf0760f7331d368, >= c762cc68b6a12eedebefc156ea4838e54804e2eb < 6b06aab79ff166d5781ce792d91acc2e58b1770b, >= c762cc68b6a12eedebefc156ea4838e54804e2eb < b7b9a8b1c303b62371698e396654d6724c79cb74, >= c762cc68b6a12eedebefc156ea4838e54804e2eb < 49c5adc2b7d6e43c5cf033e1c86fdb9c16ababb1, >= 4.10
Fixed versions
No verified fixed-version field is available yet

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
  1. 1
    Identify

    Confirm that Linux and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
Not available