Executive brief
A vulnerability exists in the Linux kernel's multitouch driver, which handles input from devices like touchscreens and touchpads. A malicious or faulty hardware device connected to the system can provide a specially crafted data structure that causes the system to crash or potentially allow unauthorized access to memory. This could lead to a complete system failure or a compromise of sensitive information handled by the operating system.
Technical details
A slab out-of-bounds access vulnerability exists in the mt_report_fixup() function within drivers/hid/hid-multitouch.c. The issue arises when the driver attempts to patch a report descriptor for Goodix GT7868Q devices at byte offset 607 without first verifying that the descriptor is at least 608 bytes long. A malicious HID device providing a smaller descriptor triggers an out-of-bounds read/write. This can be exploited by an attacker with physical access or via an adjacent network (in cases of network-attached HID) to cause a kernel panic (DoS) or potentially achieve local privilege escalation. The vulnerability has been patched in multiple stable branches by adding a mandatory size check before accessing the descriptor buffer.
Affected products
- Linux Linux Kernel 4.19.y, 5.4.y, 5.10.y, 5.15.y, 6.1.y, 6.6.y, 6.10.y, 6.11.y
Timeline
- 2025-08-10: disclosed: Initial patch submitted by Qasim Ijaz
- 2025-09-04: patched: Patches merged into stable kernel branches
- 2025-09-16: advisory: CVE-2025-39806 published
References
- https://git.kernel.org/stable/c/0379eb8691b9c4477da0277ae0832036ca4410b4
- https://git.kernel.org/stable/c/3055309821dd3da92888f88bad10f0324c3c89fe
- https://git.kernel.org/stable/c/4263e5851779f7d8ebfbc9cc7d2e9b0217adba8d
- https://git.kernel.org/stable/c/7ab7311c43ae19c66c53ccd8c5052a9072a4e338
- https://git.kernel.org/stable/c/c13e95587583d018cfbcc277df7e02d41902ac5a
- https://git.kernel.org/stable/c/d4e6e2680807671e1c73cd6a986b33659ce92f2b
- https://lists.debian.org/debian-lts-announce/2025/10/msg00008.html