Executive brief
A vulnerability was identified in the Linux kernel's touchscreen driver for EDT-FT5x06 devices. This flaw could allow a local user to trigger a system crash or potentially execute unauthorized actions by accessing specific debug files while the driver is being shut down. The issue occurs during the cleanup process of the device's diagnostic interface.
Technical details
A use-after-free (UAF) vulnerability exists in the edt-ft5x06 touchscreen driver within the Linux kernel. The issue stems from a race condition where debugfs files remain accessible after the 'edt_ft5x06_ts_teardown_debugfs' function frees the 'tsdata->raw_buffer'. An attacker with access to the debugfs interface could trigger a read operation on these files after the buffer has been deallocated. The fix involves protecting the buffer deallocation with the device mutex and explicitly setting the pointer to NULL to ensure the debugfs read function, which already performs a NULL check under the same mutex, does not attempt to access freed memory. Patches have been merged into the stable kernel tree.
Affected products
- Linux Linux Kernel edt-ft5x06 driver
Timeline
- 2026-04-10: other: Patch authored by Dmitry Torokhov
- 2026-05-27: disclosed: CVE published