What is CVE-2026-64274?
A vulnerability in the Linux kernel's Goodix touchscreen driver where the device-reported contact count is not clamped. This can lead to a buffer overflow on the stack in 'goodix_ts_read_input_report()' when the reported count exceeds 'GOODIX_MAX_CONTACTS', potentially allowing local privilege escalation or denial of service. Applying the kernel patch is required to resolve this issue.
Azərbaycanca: Linux nüvəsindəki Goodix touchscreen sürücüsündə aşkar edilmiş boşluqdur. Qurğunun bildirdiyi kontakt sayı yoxlanılmadığı üçün stack-da olan 'point_data' buferində daşma baş verə bilər. Bu zəiflik yerli istismarçıya imtiyaz artırma və ya xidmət rəddi yaratma imkanı verə bilər, problemi aradan qaldırmaq üçün kernel yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
In which component of the Linux kernel was CVE-2026-64274 discovered?
This vulnerability was discovered in the Goodix touchscreen driver of the Linux kernel.
What can a local attacker potentially achieve by exploiting CVE-2026-64274?
This vulnerability may allow a local attacker to achieve privilege escalation or cause a denial of service.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.