Junglewise Threat Intelligence

CVE-2026-64237: Linux Kernel out-of-bounds read in elan_i2c driver

CVE-2026-64237 · Severity: info · Published 2026-07-24

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability was identified in the Linux kernel's Elan I2C mouse driver. This component manages communication with certain touchpads and mice. An attacker could potentially use a specially crafted, undersized firmware file to cause the system to read memory outside of intended boundaries, which could lead to system instability or information disclosure.

Technical details

An out-of-bounds read vulnerability exists in the elan_i2c driver within the Linux kernel. The issue resides in the elan_sysfs_update_fw function in drivers/input/mouse/elan_i2c_core.c, where the driver fails to verify that a provided firmware blob is large enough to contain the expected number of pages and the signature located at the end of the blob. A local attacker with the ability to trigger a firmware update could provide a truncated firmware file, causing the kernel to read beyond the buffer's allocated memory. This has been resolved by adding a size check against the firmware signature address and signature size. Fixes are available in various stable kernel branches including 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.93, 6.18.35, and 7.0.12.

Affected products

  • Linux Linux Kernel 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.93, 6.18.35, 7.0.12

Timeline

  • 2026-07-24: disclosed
  • 2026-07-24: advisory

References

Related threats