Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-64276

CVE-2026-64276: Linux Kernel Buffer Overflow Vulnerability

CVE-2026-64276 is a buffer overflow flaw in the Linux kernel's Synaptics RMI4 driver that causes out-of-bounds memory access. This article covers the technical details, affected versions, security impact, and mitigation.

Published:

CVE-2026-64276 Overview

CVE-2026-64276 is an out-of-bounds read and write vulnerability in the Linux kernel synaptics-rmi4 input driver. The flaw resides in the F30 function handler, where rmi_f30_map_gpios() allocates a gpioled_key_map sized to at most 6 entries, while rmi_f30_attention() iterates over the device-reported gpioled_count value (range 0–31). A malicious or malformed device reporting gpioled_count > 6 with GPIO support enabled triggers out-of-bounds memory access on attention interrupts. The same defect exists in the F3A handler, which was copied from F30. The vulnerability also enables out-of-bounds read/write through the EVIOCGKEYCODE and EVIOCSKEYCODE ioctls.

Critical Impact

Local attackers with input device access can trigger kernel memory corruption, leading to information disclosure, kernel crashes, or potential privilege escalation.

Affected Products

  • Linux kernel versions containing the synaptics-rmi4 F30 and F3A handler code
  • Systems with Synaptics RMI4 input devices (touchpads, trackpoints) using GPIO/LED support
  • Distributions shipping affected stable kernel branches prior to the referenced Git commits

Discovery Timeline

  • 2026-07-25 - CVE-2026-64276 published to NVD
  • 2026-07-30 - Last updated in NVD database

Technical Details for CVE-2026-64276

Vulnerability Analysis

The defect is a classic size-mismatch between allocation and iteration bounds in kernel driver code [CWE-125/CWE-787]. In rmi_f30_map_gpios(), the driver allocates gpioled_key_map sized at min(gpioled_count, TRACKSTICK_RANGE_END), capping at 6 entries. However, rmi_f30_attention() iterates the full f30->gpioled_count value read from the device query register, which spans 0 to 31. Each iteration dereferences gpioled_key_map[i] without bounds validation against the actual allocation size.

Compounding the issue, input->keycodemax is set to the full gpioled_count, while input->keycode points at the 6-entry allocation. This misconfiguration exposes the same out-of-bounds access through the EVIOCGKEYCODE and EVIOCSKEYCODE ioctls, which validate index requests only against keycodemax. Userspace processes with access to the input device node can read arbitrary adjacent kernel memory or write attacker-controlled keycodes into out-of-bounds slots.

Root Cause

The root cause is inconsistent bounds enforcement between the keymap allocation size and the loop/ioctl bounds. The allocator uses a clamped minimum, while consumers trust the raw device-reported gpioled_count value. A malformed or malicious device can therefore control the iteration count. The F3A handler inherits the same defect because its implementation was copied from F30.

Attack Vector

Exploitation requires local access to the input subsystem, either through a physical or virtual (USB, Bluetooth, or emulated) Synaptics RMI4 device reporting an inflated gpioled_count. Once the device is attached and processed, attention interrupts trigger the out-of-bounds read. Userspace attackers holding an open file descriptor on the input node can additionally issue EVIOCGKEYCODE/EVIOCSKEYCODE ioctls to read from or write to out-of-bounds keymap indices. No specific exploit code is publicly available for this issue.

Detection Methods for CVE-2026-64276

Indicators of Compromise

  • Kernel log entries referencing rmi_f30_attention or synaptics_rmi4 faults, oopses, or KASAN reports
  • Unexpected input device registrations reporting a gpioled_count greater than 6
  • Processes issuing EVIOCSKEYCODE ioctls on RMI4 input nodes with high index values

Detection Strategies

  • Enable KASAN (Kernel Address Sanitizer) on test kernels to catch the out-of-bounds access at runtime
  • Monitor dmesg and journald for synaptics-rmi4 warnings, page faults, or slab corruption reports
  • Audit USB/HID device connection events for unrecognized RMI4 devices, especially in high-assurance environments

Monitoring Recommendations

  • Ingest kernel logs into a centralized SIEM and alert on RMI4 driver oopses or KASAN traces
  • Track evdev ioctl activity on privileged input nodes using auditd or eBPF-based telemetry
  • Correlate device attachment events with subsequent input subsystem crashes

How to Mitigate CVE-2026-64276

Immediate Actions Required

  • Apply the upstream Linux kernel patches referenced in the stable Git commits and reboot affected systems
  • Restrict physical and USB port access on systems that cannot be patched immediately
  • Disable the synaptics_rmi4 module on servers or systems that do not require RMI4 input devices

Patch Information

The fix sizes the keymap for the full gpioled_count value so that the allocation matches the iteration bounds and the keycodemax value. The mapping loop still assigns only the first min(gpioled_count, TRACKSTICK_RANGE_END) entries, preserving existing behavior for valid devices. The patch is available across multiple stable branches via the following commits: 26c895928d71, 4e3689c26854, 8c6d18d61bb6, bfe622efecd4, d162a1ead7de, d577e46785d4, e849c6f51e68, and f0be9eba946e.

Workarounds

  • Blacklist the synaptics_rmi4_core module on systems that do not require Synaptics RMI4 input hardware
  • Enforce strict USB device authorization policies to prevent untrusted HID devices from binding to the driver
  • Restrict permissions on /dev/input/event* nodes to prevent unprivileged userspace from issuing keycode ioctls

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.