CVE-2026-64364: HID: multitouch: fix out-of-bounds bit access on mt_io_flags

Greg Kroah-Hartman <[email protected]> Sat, 25 Jul 2026 10:49:41 +0200
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026072521-CVE-2026-64364-7c96@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

HID: multitouch: fix out-of-bounds bit access on mt_io_flags

mt_io_flags is a single unsigned long, but mt_process_slot(),
mt_release_pending_palms() and mt_release_contacts() use it as a
per-slot bitmap indexed by the slot number. That slot number is only
bounded by td->maxcontacts, which is taken from the device's
ContactCountMaximum feature report and can be up to 255, not by
BITS_PER_LONG.

As a result, a multitouch device that advertises a large contact count
makes set_bit()/clear_bit() operate past the mt_io_flags word and
corrupt the adjacent members of struct mt_device. The sticky-fingers
release timer is the easiest way to reach this. mt_release_contacts()
runs

	for (i = 0; i < mt->num_slots; i++)
		clear_bit(i, &td->mt_io_flags);

with num_slots == maxcontacts. For maxcontacts around 250 the loop
clears the bits that overlap td->applications.next, zeroing that list
head, and the list_for_each_entry() that immediately follows then
dereferences NULL. The kernel panics from timer (softirq) context. On a
KASAN build this shows up as a general protection fault in
mt_release_contacts() with a null-ptr-deref at offset 0x58, which is
offsetof(struct mt_application, num_received).

The state is reachable from an untrusted USB or Bluetooth HID
multitouch device; no local privileges are required.

Store the per-slot active state in a separately allocated bitmap sized
for maxcontacts, the same pattern already used for pending_palm_slots,
and keep only MT_IO_FLAGS_RUNNING in mt_io_flags. The two
"mt_io_flags & MT_IO_SLOTS_MASK" arming checks become
bitmap_empty(td->active_slots, td->maxcontacts).

Move MT_IO_FLAGS_RUNNING back to bit 0. It was bumped to bit 32 by the
same commit to leave the low byte for the slot bits; with the slot bits
gone it fits in bit 0 again, which also keeps it within the unsigned
long on 32-bit.

The Linux kernel CVE team has assigned CVE-2026-64364 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.10.246 with commit fc488f675344931ffab6a51c43691065ec006567 and fixed in 5.10.261 with commit 12e90656e330ff8bbaf2f29c535fdb8a11cc6f55
	Issue introduced in 5.15.196 with commit 77711d850bed75ae7142c3d1f22c1a8b4d049c33 and fixed in 5.15.212 with commit 152983d87387f6a8ae72b73474cfa55fbcf1ec75
	Issue introduced in 6.1.158 with commit 6acfe25968913788d30ec0eedd80178c4ea3f1d0 and fixed in 6.1.178 with commit b5c037d6b807017e74a115288f81bc9cd5a5aab8
	Issue introduced in 6.6.114 with commit d280c138e66be87d1fccfed42593f02fdb893905 and fixed in 6.6.145 with commit a6d5ce2e1a2d7bf189bde8a659d04b65f0b0725d
	Issue introduced in 6.12.55 with commit f32fea4c0234c971c12e46d76612cdc2dd4bb046 and fixed in 6.12.97 with commit e24918ee67c4dc3d20d4670750e46e9b160365f4
	Issue introduced in 6.18 with commit 46f781e0d151844589dc2125c8cce3300546f92a and fixed in 6.18.39 with commit 37daa8c96bd563d03150e23f094cb60703594a6d
	Issue introduced in 6.18 with commit 46f781e0d151844589dc2125c8cce3300546f92a and fixed in 7.1.4 with commit 6493ebf9489efef0105078377b973ab33d51af22
	Issue introduced in 6.18 with commit 46f781e0d151844589dc2125c8cce3300546f92a and fixed in 7.2-rc3 with commit 8813b0612275cc61fe9e6603d0ee019247ade6be
	Issue introduced in 6.17.5 with commit 59bd04163e6451b9c7275277882ed9f4abfa2051

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-64364
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/hid/hid-multitouch.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/12e90656e330ff8bbaf2f29c535fdb8a11cc6f55
	https://git.kernel.org/stable/c/152983d87387f6a8ae72b73474cfa55fbcf1ec75
	https://git.kernel.org/stable/c/b5c037d6b807017e74a115288f81bc9cd5a5aab8
	https://git.kernel.org/stable/c/a6d5ce2e1a2d7bf189bde8a659d04b65f0b0725d
	https://git.kernel.org/stable/c/e24918ee67c4dc3d20d4670750e46e9b160365f4
	https://git.kernel.org/stable/c/37daa8c96bd563d03150e23f094cb60703594a6d
	https://git.kernel.org/stable/c/6493ebf9489efef0105078377b973ab33d51af22
	https://git.kernel.org/stable/c/8813b0612275cc61fe9e6603d0ee019247ade6be