Junglewise Threat Intelligence

CVE-2026-64271: Linux Kernel heap overflow in Touchwindow touchscreen driver

CVE-2026-64271 · Severity: info · CVSS 6.8 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Touchwindow touchscreen driver allows a malicious or compromised hardware device to crash the system or potentially execute unauthorized code. By sending specially crafted data packets, a connected device can overflow internal memory buffers. This could lead to a complete system compromise if an attacker has physical access to plug in a rogue peripheral.

Technical details

A heap out-of-bounds write exists in the tw_interrupt() function within drivers/input/touchscreen/touchwin.c. The driver accumulates serial data into a fixed three-byte buffer (tw->data) and only resets the index (tw->idx) if a full packet is received and two specific bytes match. An attacker-controlled device can provide mismatched bytes, causing the index to increment indefinitely beyond the buffer's bounds. This results in an unbounded heap overflow, allowing a malicious peripheral to overwrite adjacent kernel memory. The issue has been resolved by ensuring the packet index is reset upon reaching the expected packet length, regardless of whether the data validation check passes.

Affected products

  • Linux Linux Kernel 11ea3173d5f2 to ed9b66905407, 044167cba238, 6c9f29f128dd, 431ad239f292, 70e424879376, 3e6f007b43e2, a8d87184576c

Timeline

  • 2026-07-25: disclosed
  • 2026-07-25: patched

References

Related threats