Junglewise Threat Intelligence

CVE-2026-64364: Linux Kernel out-of-bounds access in HID multitouch driver

CVE-2026-64364 · Severity: info · CVSS 6.8 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's multitouch driver allows a malicious USB or Bluetooth device to crash the operating system. By pretending to have a very large number of simultaneous touch points, a device can trigger memory corruption that leads to a system panic (Blue Screen equivalent). This could be used by an attacker with physical access or a nearby Bluetooth connection to disrupt operations or cause a denial of service.

Technical details

An out-of-bounds bit access exists in the HID multitouch driver (hid-multitouch.c) within the mt_io_flags member of struct mt_device. The driver uses mt_io_flags as a fixed-size bitmap (unsigned long) to track active slots, but indexes it using the 'maxcontacts' value provided by the device, which can be up to 255. A malicious USB or Bluetooth HID device advertising a high contact count can cause set_bit() or clear_bit() to operate beyond the bounds of the mt_io_flags field, corrupting adjacent structure members like td->applications.next. This leads to a null-pointer dereference and kernel panic in softirq context. The issue has been resolved by moving slot tracking to a separately allocated bitmap sized according to the device's reported maxcontacts.

Affected products

  • Linux Linux Kernel All versions prior to the July 2026 patches

Timeline

  • 2026-07-17: other: Patch submitted by Trung Nguyen
  • 2026-07-24: patched: Commits merged into stable branches by Greg Kroah-Hartman
  • 2026-07-25: disclosed: CVE-2026-64364 published

References

Related threats