CVE-2026-80566

Source
https://cve.org/CVERecord?id=CVE-2026-80566
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80566.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-80566
Downstream
Published
2026-08-26T14:37:29.552Z
Modified
2026-08-28T11:48:23.517289964Z
Summary
Input: hynitron_cstxxx - validate touch count and finger IDs
Details

In the Linux kernel, the following vulnerability has been resolved:

Input: hynitron_cstxxx - validate touch count and finger IDs

The driver allocates maxtouchnum input slots, which are indexed from zero through maxtouchnum - 1. The current check allows a finger ID equal to maxtouchnum to reach cst3xxreportcontact(). While the input core ignores out-of-range slot indices, reporting touch data without a valid slot change corrupts the touch state of the previously active slot.

The touch count is read from the controller's report and is used to index the fixed-size report buffer without first checking its range. Reject counts larger than the supported number of touch slots before checking the trailing byte or parsing touch data.

Reject finger IDs equal to or greater than maxtouchnum, and return immediately when an invalid finger ID is encountered so that corrupt touch frames are discarded instead of reporting partial contact state.

The V821 Avaota F1 board configures the vendor driver with one touch slot, so finger ID 1 is already invalid on that device.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80566.json",
    "cna_assigner": "Linux"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
66603243f5283f7f28c795f09e7c2167233df0bd
Fixed
ec61ca4e310665816a639cb2e46cd9b3af0a9bee
Fixed
387829ee60de26c7c073ed4e27ecfab2b75d4c74
Fixed
38e7d5c1ade04b99c70da0298ca296ee62bc99c0
Fixed
51c5503554c87e4de4035468bebf186205391ce9
Fixed
27f380ef0e1d3de3cde114e02d33f9320ce3a5a6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80566.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.153
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.105
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.46
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.10

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80566.json"