Executive brief
A vulnerability was identified in the Linux kernel's Elan I2C mouse driver. This component manages communication with certain touchpads and mice. An attacker could potentially use a specially crafted, undersized firmware file to cause the system to read memory outside of intended boundaries, which could lead to system instability or information disclosure.
Technical details
An out-of-bounds read vulnerability exists in the elan_i2c driver within the Linux kernel. The issue resides in the elan_sysfs_update_fw function in drivers/input/mouse/elan_i2c_core.c, where the driver fails to verify that a provided firmware blob is large enough to contain the expected number of pages and the signature located at the end of the blob. A local attacker with the ability to trigger a firmware update could provide a truncated firmware file, causing the kernel to read beyond the buffer's allocated memory. This has been resolved by adding a size check against the firmware signature address and signature size. Fixes are available in various stable kernel branches including 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.93, 6.18.35, and 7.0.12.
Affected products
- Linux Linux Kernel 5.10.259, 5.15.210, 6.1.176, 6.6.143, 6.12.93, 6.18.35, 7.0.12
Timeline
- 2026-07-24: disclosed
- 2026-07-24: advisory
References
- https://git.kernel.org/stable/c/331d49b4e1c9efe4479bbd22922dfcdd8c64be7b
- https://git.kernel.org/stable/c/3b37190ad3ded3a15fb1dbfc4f26df520a3e59bb
- https://git.kernel.org/stable/c/47b52b98edfe34d0249e72f815215ef24311c3a3
- https://git.kernel.org/stable/c/48b0aa9c08a3ac8e0c0345b7ca581f552324e460
- https://git.kernel.org/stable/c/76b0d0baa9ae9c60e726bbe1b6ff0bec2c993634
- https://git.kernel.org/stable/c/bf769358419e00344c1b16fa034d058f563d46a1
- https://git.kernel.org/stable/c/c2c3b33b3c0bf2c9427c0926817ef5ffac50de6f