CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's handling of touch data packets from the MMS134S and MMS136 touch controllers, where improper indexing leads to incorrect parsing of touch events due to a mismatch in expected event size. This flaw can result in erroneous touch input readings, potentially impacting user interaction and application behavior. Organizations utilizing these touch controllers in their Linux systems should prioritize this fix to ensure accurate touch event processing and maintain system integrity.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: Input: mms114 - fix touch indexing for MMS134S and MMS136 The MMS134S and MMS136 touch controllers have an event size of 6 bytes rather than 8 bytes. When __mms114_read_reg() reads the touch data packet from the device into the touch buffer, the events are packed tightly at 6-byte intervals. However, the driver iterates through the events using standard C array indexing (touch[index]), where each element is sizeof(struct mms114_touch) (8 bytes) apart. As a result, any touch events beyond the first one are read from incorrect offsets and parsed improperly. Fix this by explicitly calculating the byte offset for each touch event based on the device's specific event size.
Related CVEs
Other vulnerabilities affecting the same vendor(s)