CVE-2026-64364: HID: multitouch: fix out-of-bounds bit access on mt_io_flags

Published Jul 25, 2026
·
Updated

HID: multitouch: fix out-of-bounds bit access on mtioflags

Affected Software

19 affected componentsFixes available
Linux Kernel
Microsoft azl3 kernel 6.6.144.1-1<6.6.145.2-1
6.6.145.2-1
Linux Linux kernel>=5.10.246<5.10.261
Linux Linux kernel>=5.15.196<5.15.212
Linux Linux kernel>=6.1.158<6.1.178
Linux Linux kernel>=6.6.114<6.6.145
Linux Linux kernel>=6.12.55<6.12.97
Linux Linux kernel>=6.17.5<6.18
Linux Linux kernel>=6.18.1<6.18.39
Linux Linux kernel>=6.19<7.1.4
Linux Linux kernel=6.18
Linux Linux kernel=6.18-rc2
Linux Linux kernel=6.18-rc3
Linux Linux kernel=6.18-rc4
Linux Linux kernel=6.18-rc5
Linux Linux kernel=6.18-rc6
Linux Linux kernel=6.18-rc7
Linux Linux kernel=7.2-rc1
Linux Linux kernel=7.2-rc2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.6.145.2-1
  2. Configuration

    Apply the upstream fix for the HID multitouch out-of-bounds bit access by moving MT_IO_FLAGS_RUNNING back to bit 0, and store per-slot active state in a separately allocated bitmap sized by maxcontacts; do not allow per-slot bit operations to overlap adjacent members of struct mt_device via mt_io_flags.

    Linux kernel (HID multitouch driver) mt_io_flags bit layout = Move MT_IO_FLAGS_RUNNING back to bit 0 and keep only MT_IO_FLAGS_RUNNING in mt_io_flags

Event History

Jul 25, 2026
CVE Published
via MITRE·08:50 AM
Data Sourced
via MITRE·08:50 AM
DescriptionSeverity
Data Sourced
via NVD·10:17 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jul 26, 2026
Data Sourced
via Microsoft·08:10 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·08:10 AM
DescriptionSeverity

Frequently Asked Questions

1

What systems are realistically exposed to this issue?

Systems using the Linux kernel HID multitouch driver are exposed when they interact with a multitouch device whose ContactCountMaximum permits a large number of contacts. The affected slot count can be as high as 255 according to the device feature report.

2

What does an attacker need to trigger the vulnerability?

An attacker needs access to a malicious or specially crafted HID multitouch device that advertises a large contact count. No privileges or user interaction are required by the CVSS vector, and exploitation is assessed as adjacent-network attackable.

3

What is the likely impact if the issue is triggered?

Out-of-bounds bit operations corrupt adjacent members of the multitouch device structure. A demonstrated path can zero a list head and cause a NULL dereference, panicking the kernel from timer softirq context; the listed CVSS impact includes high confidentiality, integrity, and availability impact.

4

How can exposure be reduced before applying a fix?

Avoid connecting or permitting untrusted HID multitouch devices, particularly devices that can advertise unusually high ContactCountMaximum values. Restrict physical or nearby access to systems where HID devices can be attached.

5

How can I tell whether a system has encountered this issue?

Affected systems may show a kernel panic originating in timer or softirq context after multitouch contact processing. On KASAN-enabled builds, the issue can appear as a general protection fault.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203