SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-80568

HIGH · CVSS 7.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's synaptics-rmi4 driver, where changing the input type during an active video stream can lead to a heap buffer overflow due to mismatched buffer sizes. This could potentially allow an attacker to exploit the overflow, leading to arbitrary code execution or system crashes. Organizations utilizing affected Linux systems, particularly those relying on video input functionalities, should prioritize addressing this issue to mitigate potential security risks.

CVE
CVE-2026-80568
Severity
HIGH
CVSS
7.8
EPSS
0.13%
Linux F5

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - block s_input when F54 queue is busy Changing the input (diagnostic report type) mid-stream changes the report size. Since V4L2 buffers are allocated based on the size at stream start, changing the input while streaming could lead to a heap buffer overflow if the new size is larger than the allocated buffers. Prevent this by blocking VIDIOC_S_INPUT with -EBUSY if the V4L2 queue is busy (streaming).