{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-80754",
        "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "state": "PUBLISHED",
        "assignerShortName": "Linux",
        "dateReserved": "2026-08-26T14:34:25.790Z",
        "datePublished": "2026-09-03T08:26:33.180Z",
        "dateUpdated": "2026-09-04T04:58:34.715Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
                "shortName": "Linux",
                "dateUpdated": "2026-09-04T04:58:34.715Z"
            },
            "descriptions": [
                {
                    "lang": "en",
                    "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - fix F55 transmitter electrode count typo\n\nDuring F55 sensor detection, the transmitter (TX) electrode count was\nincorrectly assigned the value of the receiver (RX) electrode count\ndue to copy-paste typos.\n\nThis incorrect value was then propagated to the driver data and used\nby F54 to determine the diagnostics report size. On devices with more\nRX than TX electrodes, this inflated the perceived TX count, leading\nto incorrect report size calculations and potential out-of-bounds\nbuffer accesses.\n\nFix the typos by correctly assigning the TX electrode counts."
                }
            ],
            "metrics": [
                {
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH"
                    },
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "AV:L - Exploitation requires local V4L2 ioctls (STREAMON/QBUF) on the synaptics-rmi4 F54 diagnostics node (/dev/video* or /dev/v4l-touch*) that drive rmi_f54_buffer_queue() into rmi_f54_work(); the touch controller is on-board I2C/SPI/SMBus, not reachable over a network protocol.\nAC:L - On affected Synaptics hardware with more RX than TX electrodes and CONFIG_RMI4_F54 enabled, the inflated F55 TX count makes rmi_f54_get_report_size() exceed the F54-probe allocation deterministically; an attacker with device access can queue capture buffers without races or layout-dependent conditions.\nPR:L - No kernel capability is required beyond permission to open the registered VFL_TYPE_TOUCH video device and issue standard V4L2 capture ioctls; on typical laptops, kiosks, and Android builds this is granted to unprivileged local users via video/input device policy without init-namespace root.\nUI:N - No cooperative victim action is needed; the attacker opens the diagnostics node, selects a 16-bit F54 report type, and streams capture buffers to trigger the overflow without requiring another user to plug hardware, mount filesystems, or interact with the system.\nS:U - Impact is confined to host kernel heap memory within the same security boundary; this is a kmalloc buffer overflow in the input driver and does not inherently provide VM escape, IOMMU bypass, or cross-sandbox authority change.\nC:H - The inflated report_size causes rmi_f54_work() to read past the end of report_data and rmi_f54_buffer_queue() memcpy() copies that oversized payload into userspace, leaking adjacent kernel heap/slab contents that can include sensitive pointers and kernel memory.\nI:H - The device read loop writes attacker-influenced diagnostic bytes up to tens of kilobytes past the devm-allocated report_data buffer, corrupting adjacent heap objects and enabling control-flow hijacking or privilege-escalation primitives typical of kernel heap overflows.\nA:H - Corrupting adjacent slab objects via the out-of-bounds write can immediately panic or oops the kernel; the overflow is repeatable on each queued V4L2 buffer while the mis-probed F55 electrode counts remain in drv_data on affected hardware."
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "unaffected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/input/rmi4/rmi_f55.c"
                    ],
                    "versions": [
                        {
                            "version": "6adba43fd222ea362c36296d1a6897c2e28fdc8e",
                            "lessThan": "6484e00d6778fdf2209cd75940bc3902b276457f",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "6adba43fd222ea362c36296d1a6897c2e28fdc8e",
                            "lessThan": "db4e20265ebda729610ca5cf45ca9437462c3f36",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "6adba43fd222ea362c36296d1a6897c2e28fdc8e",
                            "lessThan": "a6d9646e77da7cab2dff7043a8e9f75e23b836bc",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "6adba43fd222ea362c36296d1a6897c2e28fdc8e",
                            "lessThan": "0739c65e799d4a93fe573ed23255a71fcfcc5438",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "6adba43fd222ea362c36296d1a6897c2e28fdc8e",
                            "lessThan": "9759502f5cd71805923457f183ae5b9533e20c7b",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "6adba43fd222ea362c36296d1a6897c2e28fdc8e",
                            "lessThan": "9b184c8337c6e12df129399007735a7fbcbbcb7b",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "6adba43fd222ea362c36296d1a6897c2e28fdc8e",
                            "lessThan": "a81cafe3c3c2f8494063385a7b0ea7ff407bf19f",
                            "status": "affected",
                            "versionType": "git"
                        },
                        {
                            "version": "6adba43fd222ea362c36296d1a6897c2e28fdc8e",
                            "lessThan": "6058f0fea10f3caf63a435677358d1b8e9325114",
                            "status": "affected",
                            "versionType": "git"
                        }
                    ]
                },
                {
                    "product": "Linux",
                    "vendor": "Linux",
                    "defaultStatus": "affected",
                    "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                    "programFiles": [
                        "drivers/input/rmi4/rmi_f55.c"
                    ],
                    "versions": [
                        {
                            "version": "4.10",
                            "status": "affected"
                        },
                        {
                            "version": "0",
                            "lessThan": "4.10",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.10.266",
                            "lessThanOrEqual": "5.10.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "5.15.217",
                            "lessThanOrEqual": "5.15.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.1.184",
                            "lessThanOrEqual": "6.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.6.153",
                            "lessThanOrEqual": "6.6.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.12.105",
                            "lessThanOrEqual": "6.12.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "6.18.46",
                            "lessThanOrEqual": "6.18.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.1.10",
                            "lessThanOrEqual": "7.1.*",
                            "status": "unaffected",
                            "versionType": "semver"
                        },
                        {
                            "version": "7.2",
                            "lessThanOrEqual": "*",
                            "status": "unaffected",
                            "versionType": "original_commit_for_fix"
                        }
                    ]
                }
            ],
            "cpeApplicability": [
                {
                    "nodes": [
                        {
                            "operator": "OR",
                            "negate": false,
                            "cpeMatch": [
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.10",
                                    "versionEndExcluding": "5.10.266"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.10",
                                    "versionEndExcluding": "5.15.217"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.10",
                                    "versionEndExcluding": "6.1.184"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.10",
                                    "versionEndExcluding": "6.6.153"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.10",
                                    "versionEndExcluding": "6.12.105"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.10",
                                    "versionEndExcluding": "6.18.46"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.10",
                                    "versionEndExcluding": "7.1.10"
                                },
                                {
                                    "vulnerable": true,
                                    "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                                    "versionStartIncluding": "4.10",
                                    "versionEndExcluding": "7.2"
                                }
                            ]
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://git.kernel.org/stable/c/6484e00d6778fdf2209cd75940bc3902b276457f"
                },
                {
                    "url": "https://git.kernel.org/stable/c/db4e20265ebda729610ca5cf45ca9437462c3f36"
                },
                {
                    "url": "https://git.kernel.org/stable/c/a6d9646e77da7cab2dff7043a8e9f75e23b836bc"
                },
                {
                    "url": "https://git.kernel.org/stable/c/0739c65e799d4a93fe573ed23255a71fcfcc5438"
                },
                {
                    "url": "https://git.kernel.org/stable/c/9759502f5cd71805923457f183ae5b9533e20c7b"
                },
                {
                    "url": "https://git.kernel.org/stable/c/9b184c8337c6e12df129399007735a7fbcbbcb7b"
                },
                {
                    "url": "https://git.kernel.org/stable/c/a81cafe3c3c2f8494063385a7b0ea7ff407bf19f"
                },
                {
                    "url": "https://git.kernel.org/stable/c/6058f0fea10f3caf63a435677358d1b8e9325114"
                }
            ],
            "title": "Input: synaptics-rmi4 - fix F55 transmitter electrode count typo",
            "x_generator": {
                "engine": "bippy-1.2.0"
            }
        }
    }
}