In the Linux kernel, the following vulnerability has been resolved:
Input: atmelmxtts - fix boundary check in mxtpreparecfg_mem
When a configuration file provides an object size that is larger than the driver's known mxtobjsize(object), the driver intends to discard the extra bytes.
The loop iterates using for (i = 0; i < size; i++). Inside the loop, the condition to skip processing extra bytes is:
if (i > mxt_obj_size(object))
continue;
Since i is a 0-based index, the valid indices for the object are 0 through mxtobjsize(object) - 1.
When i == mxtobjsize(object), the condition evaluates to false, and the code processes the byte instead of discarding it.
This causes the code to calculate byteoffset = reg + i - cfg->startofs and writes the byte there, overwriting exactly one byte of the adjacent instance or object.
Update the boundary check to skip extra bytes correctly by using >=.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63908.json",
"cna_assigner": "Linux"
}