CVE-2026-98206: Input: cyttsp5 - clamp the HID report size before memcpy
In the Linux kernel, the following vulnerability has been resolved:
Input: cyttsp5 - clamp the HID report size before memcpy
The size field comes from the device and is used as the memcpy() length into responsebuf, which is CYMAXINPUT bytes.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Clamp the device-supplied HID report size to CY_MAX_INPUT before using it as the memcpy() length into response_buf.