Executive brief
A security vulnerability was identified in the Linux kernel's Wacom tablet driver. This flaw could allow a local user or a malicious device to cause a system crash or corrupt memory by sending specially crafted input data. This affects the reliability and stability of systems using Wacom input devices.
Technical details
A slab-out-of-bounds write exists in the wacom_wac_queue_insert() function within drivers/hid/wacom_sys.c. The vulnerability is triggered when kfifo_skip() is called on an empty kfifo, leading it to read stale data from a kmalloc'd buffer and interpret it as a record length. This corrupts the internal kfifo state, causing kfifo_unused() to return an incorrect value that bypasses safety guards. Consequently, kfifo_copy_in() performs an out-of-bounds memcpy, writing up to 3842 bytes past the intended 256-byte buffer. The fix introduces a check to ensure the kfifo is not empty before skipping and validates the return value of kfifo_in().
Affected products
- Linux Linux Kernel 6.15 to 6.18.39, 7.1.4, 7.2-rc1
Timeline
- 2026-05-29: other: Patch authored
- 2026-07-25: disclosed: CVE published