{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-46232","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-05-13T15:03:33.106Z","datePublished":"2026-05-28T09:40:54.248Z","dateUpdated":"2026-08-05T12:30:38.317Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-05T12:30:38.317Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: playstation: Clamp num_touch_reports\n\nA device would never lie about the number of touch reports would it?\n\nIf it does the loop in dualshock4_parse_report will read off the end of\nthe touch_reports array, up to about 2 KiB for the maximum number of 256\nloop iteraions. The data that is read is emitted via evdev if the\nDS4_TOUCH_POINT_INACTIVE bit happens to be set. Protect against this by\nclamping the num_touch_reports value provided by the device to the\nmaximum size of the touch_reports array."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H","baseScore":8.1,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - The DualShock4 binds over both Bluetooth (HID_BLUETOOTH_DEVICE) and USB; a malicious/compromised controller within Bluetooth radio range delivers the crafted report, making Adjacent the most severe reasonable transport (higher than the USB/Physical path).\nAC:L - The device fully controls num_touch_reports and can deterministically set it to 255; the BT CRC32 uses a fixed, known seed the attacker computes. No race or attacker-uncontrolled condition is involved.\nPR:N - No privileges on the target are needed — the malicious HID device itself is the attacker, supplying crafted input reports that the kernel parses automatically.\nUI:N - A bonded controller (or a device emulating one) auto-reconnects and autonomously streams the malicious reports; no victim action triggers the out-of-bounds read.\nS:U - The impact is confined to the kernel's own memory and the input subsystem; no security boundary (VM, IOMMU, sandbox) is crossed.\nC:H - Up to ~2 KiB of adjacent kernel heap is read out of bounds, and the X/Y coordinates derived from that memory are emitted to userspace through the touchpad evdev device — a substantial kernel-memory disclosure, not bounded to a few bytes.\nI:N - The flaw is purely an out-of-bounds read; no kernel memory is written, modified, or corrupted.\nA:H - Reading up to ~2 KiB past the heap allocation can reach an unmapped page and trigger a kernel oops/panic."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/hid/hid-playstation.c"],"versions":[{"version":"752038248808a7ff176bbdb668f19ae7d2a9816b","lessThan":"0bc4cf1a6ba00fb8c074531b179bc7b97502fbc4","status":"affected","versionType":"git"},{"version":"752038248808a7ff176bbdb668f19ae7d2a9816b","lessThan":"9c031b24aed6733b6dcc5d98527875b8654a04e9","status":"affected","versionType":"git"},{"version":"752038248808a7ff176bbdb668f19ae7d2a9816b","lessThan":"7812694752a5f295eaa05a093b90a2c332666051","status":"affected","versionType":"git"},{"version":"752038248808a7ff176bbdb668f19ae7d2a9816b","lessThan":"208f6d5b1dfd6399bc6af9e11f27f1f496243ed0","status":"affected","versionType":"git"},{"version":"752038248808a7ff176bbdb668f19ae7d2a9816b","lessThan":"cac61b58a3b6340c52afa06bb15eac033158db2f","status":"affected","versionType":"git"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/hid/hid-playstation.c"],"versions":[{"version":"6.2","status":"affected"},{"version":"0","lessThan":"6.2","status":"unaffected","versionType":"semver"},{"version":"6.6.140","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.90","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.32","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.0.9","lessThanOrEqual":"7.0.*","status":"unaffected","versionType":"semver"},{"version":"7.1","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"6.6.140"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"6.12.90"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"6.18.32"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"7.0.9"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.2","versionEndExcluding":"7.1"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/0bc4cf1a6ba00fb8c074531b179bc7b97502fbc4"},{"url":"https://git.kernel.org/stable/c/9c031b24aed6733b6dcc5d98527875b8654a04e9"},{"url":"https://git.kernel.org/stable/c/7812694752a5f295eaa05a093b90a2c332666051"},{"url":"https://git.kernel.org/stable/c/208f6d5b1dfd6399bc6af9e11f27f1f496243ed0"},{"url":"https://git.kernel.org/stable/c/cac61b58a3b6340c52afa06bb15eac033158db2f"}],"title":"HID: playstation: Clamp num_touch_reports","x_generator":{"engine":"bippy-1.2.0"}}}}