CVE-2026-43047

HIGH

HID: multitouch: Check to ensure report responses match the request

Title source: cna
STIX 2.1

Description

In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: Check to ensure report responses match the request It is possible for a malicious (or clumsy) device to respond to a specific report's feature request using a completely different report ID. This can cause confusion in the HID core resulting in nasty side-effects such as OOB writes. Add a check to ensure that the report ID in the response, matches the one that was requested. If it doesn't, omit reporting the raw event and return early.

Scores

CVSS v3 7.8
EPSS 0.0001
EPSS Percentile 2.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (31)
Linux/Linux < 4.4
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 2edc92f89eee328b5be5706b5d431bf90669e9c0
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 516da3f25cfe18643835af1cf09b0e9ffc36c383
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 6a4acd3e86fe5584050c213d95147eba33856033
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 74c6015375d8b9bc1b1eb79f20636c8e894bcad7
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - 7f66fdbc077faed3b52519228d21d81979e92249
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - a61163daf8a90b4a7ef154d5fc9c525f665734e3
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - c7a27bb4d0f6573ca0f9c7ef0b63291486239190
Linux/Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 - e716edafedad4952fe3a4a273d2e039a84e8681a
Linux/Linux 4.3.6 - 4.4
... and 21 more
Published May 01, 2026
Tracked Since May 01, 2026