CVE-2026-98206 PUBLISHED

Input: cyttsp5 - clamp the HID report size before memcpy

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

Input: cyttsp5 - clamp the HID report size before memcpy

The size field comes from the device and is used as the memcpy() length into response_buf, which is CY_MAX_INPUT bytes.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 5b0c03e24a061f9c9e8b28fa157b80990c559a37 to b172c69e67bc71f71f6e3d8b3258b3dec29e42c6 (excl.)
  • affected from 5b0c03e24a061f9c9e8b28fa157b80990c559a37 to d41a80d852f2948c6d388c520e76c0a72897f003 (excl.)
  • affected from 5b0c03e24a061f9c9e8b28fa157b80990c559a37 to 9eb261092d4c967679fa351b7190c6d9082b07c5 (excl.)
  • affected from 5b0c03e24a061f9c9e8b28fa157b80990c559a37 to 495955feb57750de4a641da13d7e51fb4d0a9764 (excl.)
  • affected from 5b0c03e24a061f9c9e8b28fa157b80990c559a37 to 85f080fb87ed5cd3e46121be677f52c82f26a0ab (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 6.2 is affected
  • unaffected from 0 to 6.2 (excl.)
  • unaffected from 6.6.158 to 6.6.* (incl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References