HarborGuard / CVE
Back to search
HIGHCVE-2026-43047Published Modified CNA Linux

CVE-2026-43047: HID: multitouch: Check to ensure report responses match the request

In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: Check to ensure report responses match the request It is possible for a malicious (or clumsy) device to respond to a specific report's feature request using a completely different report ID. This can cause confusion in the HID core resulting in nasty side-effects such as OOB writes. Add a check to ensure that the report ID in the response, matches the one that was requested. If it doesn't, omit reporting the raw event and return early.

Metrics

CVSS v3.1
7.8
Severity
HIGH
Fixed in
0
Affected Products
2

Fix available

02edc92f89eee328b5be5706b5d431bf90669e9c04.45.10.2535.15.203516da3f25cfe18643835af1cf09b0e9ffc36c3836.1.1686.6.1346.12.816.18.226.19.126a4acd3e86fe5584050c213d95147eba338560337.074c6015375d8b9bc1b1eb79f20636c8e894bcad77f66fdbc077faed3b52519228d21d81979e92249a61163daf8a90b4a7ef154d5fc9c525f665734e3c7a27bb4d0f6573ca0f9c7ef0b63291486239190e716edafedad4952fe3a4a273d2e039a84e8681a
Affected packages
  • Linux / Linux
    < 516da3f25cfe18643835af1cf09b0e9ffc36c383 (from 6d4f5440a3a2bb2e9d0d582bbf98234e9e9bb095) · < a61163daf8a90b4a7ef154d5fc9c525f665734e3 (from 6d4f5440a3a2bb2e9d0d582bbf98234e9e9bb095) · < 74c6015375d8b9bc1b1eb79f20636c8e894bcad7 (from 6d4f5440a3a2bb2e9d0d582bbf98234e9e9bb095) · < c7a27bb4d0f6573ca0f9c7ef0b63291486239190 (from 6d4f5440a3a2bb2e9d0d582bbf98234e9e9bb095) · < 6a4acd3e86fe5584050c213d95147eba33856033 (from 6d4f5440a3a2bb2e9d0d582bbf98234e9e9bb095) · < 7f66fdbc077faed3b52519228d21d81979e92249 (from 6d4f5440a3a2bb2e9d0d582bbf98234e9e9bb095)
  • Linux / Linux
    4.4
    Fixed in 0, 5.10.253, 5.15.203, 6.1.168, 6.6.134, 6.12.81, 6.18.22, 6.19.12, 7.0
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H