Junglewise Threat Intelligence

CVE-2026-64367: Linux Kernel stack buffer overflow in Goodix SPI HID driver

CVE-2026-64367 · Severity: info · CVSS 0 · Published 2026-07-25

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A security vulnerability was identified in the Linux kernel's Goodix SPI driver, which manages certain touchscreens and input devices. An attacker with local access could send a specially crafted command that exceeds the system's memory limits, potentially causing a system crash or allowing unauthorized actions. This issue affects the stability and security of devices using this specific hardware driver.

Technical details

A stack-based buffer overflow exists in the 'goodix_hid_set_raw_report' function within 'drivers/hid/hid-goodix-spi.c'. The driver uses a fixed 128-byte stack buffer (tmp_buf) to construct protocol frames but fails to set 'max_buffer_size', defaulting to the HID core limit of 16,384 bytes. A local attacker can trigger this via a 'hidraw SET_REPORT' ioctl with a payload exceeding approximately 116 bytes, leading to a 'memcpy' that overflows the stack. This can result in a kernel panic or potential local privilege escalation. Patches have been merged into various stable branches including 6.12.y, 6.18.y, and 7.1.y.

Affected products

  • Linux Linux Kernel 6.12 to 6.12.96, 6.18 to 6.18.39, 7.1 to 7.1.4

Timeline

  • 2026-05-29: other: Vulnerability discovered and patch authored
  • 2026-07-25: disclosed: CVE published and advisory released

References

Related threats