CVE-2026-80567 PUBLISHED

Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue

Assigner: Linux
Reserved: 26.08.2026 Published: 26.08.2026 Updated: 26.08.2026

In the Linux kernel, the following vulnerability has been resolved:

Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue

Previously, rmi_f54_buffer_queue() waited for the worker thread to finish but ignored whether it succeeded. If the worker failed (e.g., due to a timeout or register read failure), the queue thread would silently return success, delivering stale or uninitialized memory to userspace.

Add a 'report_error' field to struct f54_data to store the worker's exit status. Check this field in rmi_f54_buffer_queue() after the worker finishes, and mark the buffer as VB2_BUF_STATE_ERROR if an error occurred.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d to 305c24ee25b6e08ac9f4c5f697e823cc638c38da (excl.)
  • affected from 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d to 7d33b752e0df385b285492b74699fc73b6becdfb (excl.)
  • affected from 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d to be56730b547737151f24357d832b04aaa93755d5 (excl.)
  • affected from 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d to 2b0403fb7e28f65883cd03814b62c9aa9bc7f04d (excl.)
  • affected from 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d to 6741a8c21d98088b7f2d9f4f86a706d311ce34a2 (excl.)
  • affected from 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d to 70f9aad3943559af6f32cb303744f35c05ce9cf1 (excl.)
  • affected from 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d to 9bbd3682f8a3e064271547133c37fcb17668d860 (excl.)
  • affected from 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d to 8786d74bf50e6797b6f655eb381ef6b25451161f (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 4.9 is affected
  • unaffected from 0 to 4.9 (excl.)
  • unaffected from 5.10.266 to 5.10.* (incl.)
  • unaffected from 5.15.217 to 5.15.* (incl.)
  • unaffected from 6.1.184 to 6.1.* (incl.)
  • unaffected from 6.6.153 to 6.6.* (incl.)
  • unaffected from 6.12.105 to 6.12.* (incl.)
  • unaffected from 6.18.46 to 6.18.* (incl.)
  • unaffected from 7.1.10 to 7.1.* (incl.)
  • unaffected from 7.2 to * (incl.)

References