Executive brief
A vulnerability in the Linux kernel's multitouch driver allows a malicious USB or Bluetooth device to crash the operating system. By pretending to have a very large number of simultaneous touch points, a device can trigger memory corruption that leads to a system panic (Blue Screen equivalent). This could be used by an attacker with physical access or a nearby Bluetooth connection to disrupt operations or cause a denial of service.
Technical details
An out-of-bounds bit access exists in the HID multitouch driver (hid-multitouch.c) within the mt_io_flags member of struct mt_device. The driver uses mt_io_flags as a fixed-size bitmap (unsigned long) to track active slots, but indexes it using the 'maxcontacts' value provided by the device, which can be up to 255. A malicious USB or Bluetooth HID device advertising a high contact count can cause set_bit() or clear_bit() to operate beyond the bounds of the mt_io_flags field, corrupting adjacent structure members like td->applications.next. This leads to a null-pointer dereference and kernel panic in softirq context. The issue has been resolved by moving slot tracking to a separately allocated bitmap sized according to the device's reported maxcontacts.
Affected products
- Linux Linux Kernel All versions prior to the July 2026 patches
Timeline
- 2026-07-17: other: Patch submitted by Trung Nguyen
- 2026-07-24: patched: Commits merged into stable branches by Greg Kroah-Hartman
- 2026-07-25: disclosed: CVE-2026-64364 published
References
- https://git.kernel.org/stable/c/12e90656e330ff8bbaf2f29c535fdb8a11cc6f55
- https://git.kernel.org/stable/c/152983d87387f6a8ae72b73474cfa55fbcf1ec75
- https://git.kernel.org/stable/c/37daa8c96bd563d03150e23f094cb60703594a6d
- https://git.kernel.org/stable/c/6493ebf9489efef0105078377b973ab33d51af22
- https://git.kernel.org/stable/c/8813b0612275cc61fe9e6603d0ee019247ade6be
- https://git.kernel.org/stable/c/a6d5ce2e1a2d7bf189bde8a659d04b65f0b0725d
- https://git.kernel.org/stable/c/b5c037d6b807017e74a115288f81bc9cd5a5aab8