{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64364","assignerOrgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","state":"PUBLISHED","assignerShortName":"Linux","dateReserved":"2026-07-19T15:36:31.783Z","datePublished":"2026-07-25T08:50:19.441Z","dateUpdated":"2026-08-17T04:54:11.199Z"},"containers":{"cna":{"providerMetadata":{"orgId":"416baaa9-dc9f-4396-8d5f-8c081fb06d67","shortName":"Linux","dateUpdated":"2026-08-17T04:54:11.199Z"},"descriptions":[{"lang":"en","value":"In the Linux kernel, the following vulnerability has been resolved:\n\nHID: multitouch: fix out-of-bounds bit access on mt_io_flags\n\nmt_io_flags is a single unsigned long, but mt_process_slot(),\nmt_release_pending_palms() and mt_release_contacts() use it as a\nper-slot bitmap indexed by the slot number. That slot number is only\nbounded by td->maxcontacts, which is taken from the device's\nContactCountMaximum feature report and can be up to 255, not by\nBITS_PER_LONG.\n\nAs a result, a multitouch device that advertises a large contact count\nmakes set_bit()/clear_bit() operate past the mt_io_flags word and\ncorrupt the adjacent members of struct mt_device. The sticky-fingers\nrelease timer is the easiest way to reach this. mt_release_contacts()\nruns\n\n\tfor (i = 0; i < mt->num_slots; i++)\n\t\tclear_bit(i, &td->mt_io_flags);\n\nwith num_slots == maxcontacts. For maxcontacts around 250 the loop\nclears the bits that overlap td->applications.next, zeroing that list\nhead, and the list_for_each_entry() that immediately follows then\ndereferences NULL. The kernel panics from timer (softirq) context. On a\nKASAN build this shows up as a general protection fault in\nmt_release_contacts() with a null-ptr-deref at offset 0x58, which is\noffsetof(struct mt_application, num_received).\n\nThe state is reachable from an untrusted USB or Bluetooth HID\nmultitouch device; no local privileges are required.\n\nStore the per-slot active state in a separately allocated bitmap sized\nfor maxcontacts, the same pattern already used for pending_palm_slots,\nand keep only MT_IO_FLAGS_RUNNING in mt_io_flags. The two\n\"mt_io_flags & MT_IO_SLOTS_MASK\" arming checks become\nbitmap_empty(td->active_slots, td->maxcontacts).\n\nMove MT_IO_FLAGS_RUNNING back to bit 0. It was bumped to bit 32 by the\nsame commit to leave the low byte for the slot bits; with the slot bits\ngone it fits in bit 0 again, which also keeps it within the unsigned\nlong on 32-bit."}],"metrics":[{"cvssV3_1":{"version":"3.1","vectorString":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH"},"scenarios":[{"lang":"en","value":"AV:A - A malicious Bluetooth HID multitouch peripheral within radio range can supply the descriptor, feature value, and input reports; malicious USB devices provide an additional physical path.\nAC:L - Advertising 250 contacts, sending one active contact, and remaining silent for 100 ms deterministically triggers the timer path without a race, heap grooming, or uncontrollable condition.\nPR:N - The external HID device needs no target-system account or capability, and normal HID connection handling delivers its attacker-controlled data to the driver.\nUI:N - An already-connected or automatically reconnecting Bluetooth peripheral can trigger the flaw without victim action; report processing itself requires no file, prompt, or application interaction.\nS:U - The corruption occurs in the host kernel and compromises resources governed by that same kernel security authority.\nC:H - Attacker-controlled out-of-bounds bit operations cover adjacent list pointers and can redirect subsequent kernel memory accesses, supporting kernel compromise and arbitrary disclosure.\nI:H - The device obtains attacker-directed set/clear operations over adjacent pointer fields, enabling crafted pointer corruption, further kernel writes, and potentially code execution.\nA:H - The deterministic timeout path corrupts the applications list and causes a kernel panic from softirq context, and a malicious peripheral can trigger it repeatedly."}]}],"affected":[{"product":"Linux","vendor":"Linux","defaultStatus":"unaffected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/hid/hid-multitouch.c"],"versions":[{"version":"fc488f675344931ffab6a51c43691065ec006567","lessThan":"12e90656e330ff8bbaf2f29c535fdb8a11cc6f55","status":"affected","versionType":"git"},{"version":"77711d850bed75ae7142c3d1f22c1a8b4d049c33","lessThan":"152983d87387f6a8ae72b73474cfa55fbcf1ec75","status":"affected","versionType":"git"},{"version":"6acfe25968913788d30ec0eedd80178c4ea3f1d0","lessThan":"b5c037d6b807017e74a115288f81bc9cd5a5aab8","status":"affected","versionType":"git"},{"version":"d280c138e66be87d1fccfed42593f02fdb893905","lessThan":"a6d5ce2e1a2d7bf189bde8a659d04b65f0b0725d","status":"affected","versionType":"git"},{"version":"f32fea4c0234c971c12e46d76612cdc2dd4bb046","lessThan":"e24918ee67c4dc3d20d4670750e46e9b160365f4","status":"affected","versionType":"git"},{"version":"46f781e0d151844589dc2125c8cce3300546f92a","lessThan":"37daa8c96bd563d03150e23f094cb60703594a6d","status":"affected","versionType":"git"},{"version":"46f781e0d151844589dc2125c8cce3300546f92a","lessThan":"6493ebf9489efef0105078377b973ab33d51af22","status":"affected","versionType":"git"},{"version":"46f781e0d151844589dc2125c8cce3300546f92a","lessThan":"8813b0612275cc61fe9e6603d0ee019247ade6be","status":"affected","versionType":"git"},{"version":"59bd04163e6451b9c7275277882ed9f4abfa2051","status":"affected","versionType":"git"},{"version":"5.10.246","lessThan":"5.10.261","status":"affected","versionType":"semver"},{"version":"5.15.196","lessThan":"5.15.212","status":"affected","versionType":"semver"},{"version":"6.1.158","lessThan":"6.1.178","status":"affected","versionType":"semver"},{"version":"6.6.114","lessThan":"6.6.145","status":"affected","versionType":"semver"},{"version":"6.12.55","lessThan":"6.12.97","status":"affected","versionType":"semver"},{"version":"6.17.5","lessThan":"6.18","status":"affected","versionType":"semver"}]},{"product":"Linux","vendor":"Linux","defaultStatus":"affected","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","programFiles":["drivers/hid/hid-multitouch.c"],"versions":[{"version":"6.18","status":"affected"},{"version":"0","lessThan":"6.18","status":"unaffected","versionType":"semver"},{"version":"5.10.261","lessThanOrEqual":"5.10.*","status":"unaffected","versionType":"semver"},{"version":"5.15.212","lessThanOrEqual":"5.15.*","status":"unaffected","versionType":"semver"},{"version":"6.1.178","lessThanOrEqual":"6.1.*","status":"unaffected","versionType":"semver"},{"version":"6.6.145","lessThanOrEqual":"6.6.*","status":"unaffected","versionType":"semver"},{"version":"6.12.97","lessThanOrEqual":"6.12.*","status":"unaffected","versionType":"semver"},{"version":"6.18.39","lessThanOrEqual":"6.18.*","status":"unaffected","versionType":"semver"},{"version":"7.1.4","lessThanOrEqual":"7.1.*","status":"unaffected","versionType":"semver"},{"version":"7.2","lessThanOrEqual":"*","status":"unaffected","versionType":"original_commit_for_fix"}]}],"cpeApplicability":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.10.246","versionEndExcluding":"5.10.261"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"5.15.196","versionEndExcluding":"5.15.212"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.1.158","versionEndExcluding":"6.1.178"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.6.114","versionEndExcluding":"6.6.145"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.12.55","versionEndExcluding":"6.12.97"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"6.18.39"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.1.4"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.18","versionEndExcluding":"7.2"},{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionStartIncluding":"6.17.5"}]}]}],"references":[{"url":"https://git.kernel.org/stable/c/12e90656e330ff8bbaf2f29c535fdb8a11cc6f55"},{"url":"https://git.kernel.org/stable/c/152983d87387f6a8ae72b73474cfa55fbcf1ec75"},{"url":"https://git.kernel.org/stable/c/b5c037d6b807017e74a115288f81bc9cd5a5aab8"},{"url":"https://git.kernel.org/stable/c/a6d5ce2e1a2d7bf189bde8a659d04b65f0b0725d"},{"url":"https://git.kernel.org/stable/c/e24918ee67c4dc3d20d4670750e46e9b160365f4"},{"url":"https://git.kernel.org/stable/c/37daa8c96bd563d03150e23f094cb60703594a6d"},{"url":"https://git.kernel.org/stable/c/6493ebf9489efef0105078377b973ab33d51af22"},{"url":"https://git.kernel.org/stable/c/8813b0612275cc61fe9e6603d0ee019247ade6be"}],"title":"HID: multitouch: fix out-of-bounds bit access on mt_io_flags","x_generator":{"engine":"bippy-1.2.0"}}}}