CVE-2026-63908

Source
https://cve.org/CVERecord?id=CVE-2026-63908
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63908.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-63908
Downstream
Published
2026-07-19T14:55:14.349Z
Modified
2026-07-21T03:47:37.803473926Z
Summary
Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem
Details

In the Linux kernel, the following vulnerability has been resolved:

Input: atmelmxtts - fix boundary check in mxtpreparecfg_mem

When a configuration file provides an object size that is larger than the driver's known mxtobjsize(object), the driver intends to discard the extra bytes.

The loop iterates using for (i = 0; i < size; i++). Inside the loop, the condition to skip processing extra bytes is:

if (i > mxt_obj_size(object))
    continue;

Since i is a 0-based index, the valid indices for the object are 0 through mxtobjsize(object) - 1.

When i == mxtobjsize(object), the condition evaluates to false, and the code processes the byte instead of discarding it.

This causes the code to calculate byteoffset = reg + i - cfg->startofs and writes the byte there, overwriting exactly one byte of the adjacent instance or object.

Update the boundary check to skip extra bytes correctly by using >=.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63908.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
50a77c658b80e7e3303e3bcec195b30e2b62d513
Fixed
862a1a32b5190241fce7a7d20229539a3926f31e
Fixed
5c3681c3abc35cfac6b702251382312c60d96bc2
Fixed
1017e1c6c6c49cccbcda9bbcfa49e50b0b6dad39
Fixed
e9b62996ba537774f68fecfd7eecb5aec1713952
Fixed
ae92e334544263a02d9f99e18385e718c44392c9
Fixed
7f95f4792c0dc767fcb8e405391e779ab419d55a
Fixed
6c6b989b4ebf22b086fdfcac2163b5cb55e34d8f
Fixed
baa0210fb6a9dc3882509a9411b6d284d88fe30e

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63908.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
3.17.0
Fixed
5.10.259
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.210
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.176
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.143
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.93
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.35
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.0.12

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-63908.json"