What is CVE-2026-64270?
CVE-2026-64270 is a vulnerability in the Linux kernel's mms114 touchscreen driver. It occurs because mms114_interrupt() fails to reject an oversized device packet before copying it into a fixed-size on-stack buffer, potentially leading to a stack buffer overflow that could cause privilege escalation or denial of service. Affected systems should be updated with the patched kernel version that enforces packet size validation.
Azərbaycanca: CVE-2026-64270, Linux kernel-də mms114 sensor sürücüsündə tapılan zəiflikdir. Bu, mms114_interrupt() funksiyasında həddindən artıq böyük paket ölçüsünün rədd edilməməsi səbəbindən yaranır və stack-da yerləşən sabit ölçülü buferin overflow olmasına, nəticədə privilege escalation və ya DoS hücumlarına yol aça bilər. Bu zəiflikdən qorunmaq üçün kernel-i ən son patch edilmiş versiyaya yeniləmək lazımdır.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
In which component of the Linux kernel was CVE-2026-64270 discovered?
The vulnerability was found in the Linux kernel's mms114 touchscreen driver.
What are the potential consequences if CVE-2026-64270 is exploited?
Exploitation could lead to privilege escalation or denial of service (DoS).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.