In the Linux kernel, the following vulnerability has been resolved: HID: hid-goodix-spi: validate report size to prevent stack buffer overflow… (CVE-2026-64367)
A stack buffer overflow vulnerability was identified and resolved in the Linux kernel's hid-goodix-spi driver. The vulnerability arises because the driver does not properly validate the size of the report data before copying it into a fixed-size 128-byte stack buffer, allowing an attacker to overflow the buffer with a specially crafted HID report larger than approximately 116 bytes. This issue was addressed by adding a size check to reject oversized reports, preventing the overflow.
AI Analysis
Technical Summary
The Linux kernel hid-goodix-spi driver previously lacked proper bounds checking on the size of HID reports copied into a 128-byte stack buffer. The function goodix_hid_set_raw_report() constructs a protocol frame with an 11-12 byte header followed by caller-supplied report data. While the HID core limits report size to 16384 bytes by default, the driver did not set max_buffer_size or validate the payload length before copying it via memcpy, leading to a potential stack buffer overflow when a report larger than about 116 bytes is processed. The vulnerability was fixed by adding a size check after header construction to reject reports exceeding the buffer capacity.
Potential Impact
An attacker able to send a crafted HID SET_REPORT ioctl with a report larger than approximately 116 bytes could overflow the 128-byte stack buffer in the hid-goodix-spi driver. This could lead to memory corruption, potentially causing denial of service or arbitrary code execution within kernel context. However, no known exploits in the wild have been reported.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to add proper size validation and prevent stack buffer overflow in the hid-goodix-spi driver. Users and administrators should apply the official kernel updates that include this patch once available. Patch status is not yet confirmed from vendor advisory; check the Linux kernel security advisories for the current remediation guidance.
In the Linux kernel, the following vulnerability has been resolved: HID: hid-goodix-spi: validate report size to prevent stack buffer overflow… (CVE-2026-64367)
Description
A stack buffer overflow vulnerability was identified and resolved in the Linux kernel's hid-goodix-spi driver. The vulnerability arises because the driver does not properly validate the size of the report data before copying it into a fixed-size 128-byte stack buffer, allowing an attacker to overflow the buffer with a specially crafted HID report larger than approximately 116 bytes. This issue was addressed by adding a size check to reject oversized reports, preventing the overflow.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Linux kernel hid-goodix-spi driver previously lacked proper bounds checking on the size of HID reports copied into a 128-byte stack buffer. The function goodix_hid_set_raw_report() constructs a protocol frame with an 11-12 byte header followed by caller-supplied report data. While the HID core limits report size to 16384 bytes by default, the driver did not set max_buffer_size or validate the payload length before copying it via memcpy, leading to a potential stack buffer overflow when a report larger than about 116 bytes is processed. The vulnerability was fixed by adding a size check after header construction to reject reports exceeding the buffer capacity.
Potential Impact
An attacker able to send a crafted HID SET_REPORT ioctl with a report larger than approximately 116 bytes could overflow the 128-byte stack buffer in the hid-goodix-spi driver. This could lead to memory corruption, potentially causing denial of service or arbitrary code execution within kernel context. However, no known exploits in the wild have been reported.
Mitigation Recommendations
A fix has been implemented in the Linux kernel to add proper size validation and prevent stack buffer overflow in the hid-goodix-spi driver. Users and administrators should apply the official kernel updates that include this patch once available. Patch status is not yet confirmed from vendor advisory; check the Linux kernel security advisories for the current remediation guidance.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-p4f3-xcv2-3qcx
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-64367"]
- Ecosystems
- []
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a65420a9c2644c7f8084485
Added to database: 07/25/2026, 23:08:58 UTC
Last enriched: 07/25/2026, 23:28:13 UTC
Last updated: 07/26/2026, 03:45:32 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.