Junglewise Threat Intelligence

CVE-2026-89620: Linux kernel HID intel-quickspi heap buffer overflow

CVE-2026-89620 · Severity: high · CVSS 7.8 · Published 2026-09-11

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

The Linux kernel's HID intel-quickspi driver processes touch controller input through a report buffer on the heap. An attacker can send a maliciously crafted HID report larger than expected, overwriting adjacent heap memory and potentially executing arbitrary code or crashing the system. This affects systems with Intel HID touch controllers using the quickspi protocol.

Technical details

A heap buffer overflow exists in the intel-quickspi HID driver's write_cmd_to_txdma() function, which copies caller-supplied HID reports into a fixed-size report buffer (typically a few hundred bytes) without validating the report length. The HID core allows reports up to HID_MAX_BUFFER_SIZE (16384 bytes) by default, and the quickspi driver does not restrict max_buffer_size, allowing an unbounded report to reach the driver. An attacker with access to a hidraw device can trigger a SET_REPORT or SET_FEATURE ioctl with an oversized report, causing a memcpy() to overflow the heap buffer with attacker-controlled length and content. The fix adds size validation before the copy and properly sizes the buffer allocation to account for the report header written by write_cmd_to_txdma(). The vulnerability was introduced in commit 9d8d51735a3a and is fixed by validating against the recorded report_buf_size.

Affected products

  • Linux Linux kernel 4.0+

Timeline

  • 2026-09-11: disclosed
  • 2026-08-03: patched

References

Related threats