HID: hid-goodix-spi: validate report size to prevent stack buffer overflow
Published Jul 25, 2026
7.8
HIGHCVSS 3.1
EPSS 0.14%
Description
goodix_hid_set_raw_report() builds a protocol frame in a 128-byte stack buffer (tmp_buf), writing an 11-12 byte header followed by the caller-supplied report data. The HID core caps report size at HID_MAX_BUFFER_SIZE (16384) by default, while the driver does not set hid_ll_driver.max_buffer_size and performs no bounds checking before copying the payload:
memcpy(tmp_buf + tx_len, buf, len);
A hidraw SET_REPORT ioctl with a report larger than ~116 bytes overflows the stack buffer.
Add a size check after constructing the header, rejecting reports that would exceed the buffer capacity.
Discovered by Atuin - Automated Vulnerability Discovery Engine.
Affected products
-
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version StatusaffectedConstraints
- Version
-
- Version 6.12StatusaffectedConstraints-
- Version 0StatusunaffectedConstraints<6.12
- Version 6.12.96StatusunaffectedConstraints<=6.12.*
- Version 6.18.39StatusunaffectedConstraints<=6.18.*
- Version 7.1.4StatusunaffectedConstraints<=7.1.*
- Version 7.2StatusunaffectedConstraints<=*
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
- ≥ 6.12 · < 6.12.96
- ≥ 6.13 · < 6.18.39
- ≥ 6.19 · < 7.1.4
No data.
Red Hat Enterprise Linux 10
kernel
Not affected
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-rt
Not affected
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise Linux 9
kernel
Not affected
Red Hat Enterprise Linux 9
kernel-rt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 9 | kernel-rt | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2026-64367 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2507231 Issue Tracking
- https://git.kernel.org/stable/c/835fcc8655569737e3f057d42875a96259db74c2 Patch
- https://git.kernel.org/stable/c/ad47ad624f2fce0bc44bbadb664242461a97d774 Patch
- https://git.kernel.org/stable/c/dae1d000ddfd5c2140b036e47fff0c497ae9c64b Patch
- https://git.kernel.org/stable/c/db0a0768d09273aadadeb76730cd658d720333a4 Patch
- https://lore.kernel.org/linux-cve-announce/2026072522-CVE-2026-64367-c35d@gregkh/T
- https://nvd.nist.gov/vuln/detail/CVE-2026-64367
- https://www.cve.org/CVERecord?id=CVE-2026-64367
Change history (0)
No recorded changes yet.