CVE 7.8 HIGH

HID: multitouch: Check to ensure report responses match the request_CVE-2026-43047

7.8 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

In the Linux kernel, the following vulnerability has been resolved:

HID: multitouch: Check to ensure report responses match the request

It is possible for a malicious (or clumsy) device to respond to a
specific report's feature request using a completely different report
ID. This can cause confusion in the HID core resulting in nasty
side-effects such as OOB writes.

Add a check to ensure that the report ID in the response, matches the
one that was requested. If it doesn't, omit reporting the raw event and
return early.

Basic Information

ID CVE-2026-43047
Source Linux
Published May 1, 2026 at 14:15
Modified May 3, 2026 at 05:46

Affected Product

Vendor Linux
Product Linux
Version 6d4f5440a3a2bb2e9d0d582bbf98234e9e9bb095
Affected Versions Linux Linux 6d4f5440a3a2bb2e9d0d582bbf98234e9e9bb095
Linux Linux 6d4f5440a3a2bb2e9d0d582bbf98234e9e9bb095
Linux Linux 6d4f5440a3a2bb2e9d0d582bbf98234e9e9bb095
Linux Linux 6d4f5440a3a2bb2e9d0d582bbf98234e9e9bb095
Linux Linux 6d4f5440a3a2bb2e9d0d582bbf98234e9e9bb095
Linux Linux 6d4f5440a3a2bb2e9d0d582bbf98234e9e9bb095
Linux Linux 6d4f5440a3a2bb2e9d0d582bbf98234e9e9bb095
Linux Linux 6d4f5440a3a2bb2e9d0d582bbf98234e9e9bb095
Linux Linux fee906f035f0bd18ff12d84d58766c44a2ab0918
Linux Linux 4.4

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.