CVE-2026-80566: Input: hynitron_cstxxx - validate touch count and finger IDs
In the Linux kernel, the following vulnerability has been resolved:
Input: hynitroncstxxx - validate touch count and finger IDs
The driver allocates maxtouchnum input slots, which are indexed from zero through maxtouchnum - 1. The current check allows a finger ID equal to maxtouchnum to reach cst3xxreportcontact(). While the input core ignores out-of-range slot indices, reporting touch data without a valid slot change corrupts the touch state of the previously active slot.
The touch count is read from the controller's report and is used to index the fixed-size report buffer without first checking its range. Reject counts larger than the supported number of touch slots before checking the trailing byte or parsing touch data.
Reject finger IDs equal to or greater than maxtouchnum, and return immediately when an invalid finger ID is encountered so that corrupt touch frames are discarded instead of reporting partial contact state.
The V821 Avaota F1 board configures the vendor driver with one touch slot, so finger ID 1 is already invalid on that device.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
Systems using the Linux hynitron_cstxxx touchscreen driver are affected. The V821 Avaota F1 board is specifically exposed because its vendor driver configuration provides only one touch slot, making finger ID 1 invalid.
What input is needed to trigger the faulty behavior?
The touchscreen controller must report a touch count larger than the supported slot count, or report a finger ID equal to or greater than max_touch_num. An invalid finger ID can cause touch data to be reported without a valid slot change, corrupting the state of a previously active touch slot.
How does the fix handle malformed touch reports?
The fix rejects touch counts exceeding the supported number of slots before indexing the fixed-size report buffer. It also rejects finger IDs at or above max_touch_num and discards the entire frame immediately when an invalid ID is encountered, preventing partial contact-state reporting.