In the Linux kernel, the following vulnerability has been resolved:
Input: cyttsp5 - clamp the HID report size before memcpy
The size field comes from the device and is used as the memcpy() length into response_buf, which is CY_MAX_INPUT bytes.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106341.json"