Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-80570— Input: synaptics-rmi4 - zero report size on F54 work error

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

以下是该漏洞描述的中文翻译: 在 Linux 内核中,以下漏洞已修复: 输入:synaptics-rmi4 - F54 处理错误时报告大小为零 在 函数中,如果在请求报告或验证命令过程中发生错误,代码会直接跳转到 标签,从而跳过了 标签。而在 标签处,通常会执行 的操作。 这导致 保留着之前成功时的负载大小。如果用户随后将 V4L2 格式更改为更小的尺寸,并且下一次运行再次失败, 就会将这个过时的、更大的负载大小复制到缩小后的 V4L2 缓冲区中,从而引发堆缓冲区溢出。 修复方法**:将 和 标签合并为单一的 退出

CVSS 7.8 · High EPSS 0.13% · P3

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d< 62079c17ec07d64362bec367ee7a525b0dbf6bf9 affected
3a762dbd5347514c3cb2ac756a92a3d1c7646a2d< 79521ed3cc9ea48476666ccacf45ecd6954b29a4 affected
3a762dbd5347514c3cb2ac756a92a3d1c7646a2d< c669c64ab71afa7b467c4d7e18f6a05e96b97a1f affected
3a762dbd5347514c3cb2ac756a92a3d1c7646a2d< 77749685e55da19b187df215b5da4080842ca5c7 affected
3a762dbd5347514c3cb2ac756a92a3d1c7646a2d< c6cfda79f26c69e97db9805808c3b44d02227b4b affected
3a762dbd5347514c3cb2ac756a92a3d1c7646a2d< b28593a05afdd812b590e1045b5bd862a5869225 affected
3a762dbd5347514c3cb2ac756a92a3d1c7646a2d< 88c8174d72900d77fbdf2f527d54b6ff2da876a8 affected
3a762dbd5347514c3cb2ac756a92a3d1c7646a2d< dc76c3c8e8ad09362b8c1561f3928288c15cba2e affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80570

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Input: synaptics-rmi4 - zero report size on F54 work error
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - zero report size on F54 work error In rmi_f54_work(), if an error occurs during report request or command verification, the code jumped directly to the 'error' label, bypassing the 'abort' label where f54->report_size was normally zeroed out. This left f54->report_size containing its previous successful payload size. If a user then altered the V4L2 format to a smaller size, and a subsequent run failed, rmi_f54_buffer_queue() would copy the stale, larger payload size into the shrunken V4L2 buffer, causing a heap buffer overflow. Fix this by merging the 'abort' and 'error' labels into a single 'out' exit path, and ensuring that f54->report_size is always set to 0 on failure by checking for error and zeroing the local report_size first.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 3a762dbd5347514c3cb2ac756a92a3d1c7646a2d ~ 62079c17ec07d64362bec367ee7a525b0dbf6bf9 -
Linux Linux 4.9 -

II. Public POCs for CVE-2026-80570

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80570

登录查看更多情报信息。

Patches & Fixes for CVE-2026-80570 (7)

Vendor Advisories for CVE-2026-80570 (1)

Same Patch Batch · Linux · 2026-08-26 · 92 CVEs total

CVE-2026-80589 9.8 CRITICAL block: stop the timeout timer when releasing a never added disk
CVE-2026-74752 9.8 CRITICAL sctp: validate cookie AUTH state before use
CVE-2026-80519 9.8 CRITICAL ovpn: finish crypto callback cleanup before peer release
CVE-2026-80528 9.8 CRITICAL ceph: avoid fs reclaim while using current->journal_info
CVE-2026-74746 9.8 CRITICAL netfilter: flowtable: publish GC-visible tuple last
CVE-2026-80561 9.8 CRITICAL libceph: fix multiple unsafe decodes in decode_locker()
CVE-2026-74744 9.8 CRITICAL ipvlan: inherit needed_headroom and needed_tailroom from phy_dev
CVE-2026-74743 9.8 CRITICAL macvlan: inherit needed_headroom and needed_tailroom from lowerdev
CVE-2026-80558 9.8 CRITICAL libceph: Avoid using invalid osd indices from primary_temp
CVE-2026-80586 9.8 CRITICAL mptcp: options: reset DSS fields in case of unexpected size
CVE-2026-80557 9.8 CRITICAL libceph: fix OOB read in decode_watchers() via missing bounds check
CVE-2026-74737 9.8 CRITICAL net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG
CVE-2026-80587 9.8 CRITICAL mptcp: avoid combining some incoming suboptions
CVE-2026-80585 9.4 CRITICAL mptcp: fastopen: only mark MPTFO subflows with SYN data
CVE-2026-74751 9.4 CRITICAL riscv: lib: Fix ZBB strnlen reading past count boundary
CVE-2026-80554 9.3 CRITICAL s390/vfio_ccw: Limit the number of channel program segments
CVE-2026-80551 9.3 CRITICAL s390/vfio_ccw: Ensure first IDAW remains constant
CVE-2026-80547 8.8 HIGH s390/vfio_ccw: Implement a crw lock
CVE-2026-80576 8.8 HIGH drm/amdgpu: reject oversized IBs with per-ring packet limits
CVE-2026-80552 8.8 HIGH s390/vfio_ccw: Ensure index for read/write regions are within range

Showing top 20 of 92 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-80570

No comments yet


Leave a comment