CVE-2026-98206

Source
https://cve.org/CVERecord?id=CVE-2026-98206
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98206.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-98206
Downstream
Published
2026-10-06T08:44:43Z
Modified
2026-10-07T02:47:29Z
Summary
Input: cyttsp5 - clamp the HID report size before memcpy
Details

In the Linux kernel, the following vulnerability has been resolved:

Input: cyttsp5 - clamp the HID report size before memcpy

The size field comes from the device and is used as the memcpy() length into response_buf, which is CY_MAX_INPUT bytes.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98206.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
5b0c03e24a061f9c9e8b28fa157b80990c559a37
Fixed
b172c69e67bc71f71f6e3d8b3258b3dec29e42c6
Fixed
d41a80d852f2948c6d388c520e76c0a72897f003
Fixed
9eb261092d4c967679fa351b7190c6d9082b07c5
Fixed
495955feb57750de4a641da13d7e51fb4d0a9764
Fixed
85f080fb87ed5cd3e46121be677f52c82f26a0ab

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98206.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.158
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.112
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.54
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98206.json"