CVE-2026-46232

In the Linux kernel, the following vulnerability has been resolved: HID: playstation: Clamp num_touch_reports A device would never lie about the number of touch reports would it? If it does the loop in dualshock4_parse_report will read off the end of the touch_reports array, up to about 2 KiB for the maximum number of 256 loop iteraions. The data that is read is emitted via evdev if the DS4_TOUCH_POINT_INACTIVE bit happens to be set. Protect against this by clamping the num_touch_reports value provided by the device to the maximum size of the touch_reports array.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*

History

10 Jun 2026, 21:11

Type Values Removed Values Added
References () https://git.kernel.org/stable/c/0bc4cf1a6ba00fb8c074531b179bc7b97502fbc4 - () https://git.kernel.org/stable/c/0bc4cf1a6ba00fb8c074531b179bc7b97502fbc4 - Patch
References () https://git.kernel.org/stable/c/208f6d5b1dfd6399bc6af9e11f27f1f496243ed0 - () https://git.kernel.org/stable/c/208f6d5b1dfd6399bc6af9e11f27f1f496243ed0 - Patch
References () https://git.kernel.org/stable/c/7812694752a5f295eaa05a093b90a2c332666051 - () https://git.kernel.org/stable/c/7812694752a5f295eaa05a093b90a2c332666051 - Patch
References () https://git.kernel.org/stable/c/9c031b24aed6733b6dcc5d98527875b8654a04e9 - () https://git.kernel.org/stable/c/9c031b24aed6733b6dcc5d98527875b8654a04e9 - Patch
References () https://git.kernel.org/stable/c/cac61b58a3b6340c52afa06bb15eac033158db2f - () https://git.kernel.org/stable/c/cac61b58a3b6340c52afa06bb15eac033158db2f - Patch
First Time Linux linux Kernel
Linux
CWE NVD-CWE-noinfo
CPE cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:7.1:rc3:*:*:*:*:*:*

30 May 2026, 11:17

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1

28 May 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-28 10:16

Updated : 2026-06-10 21:11


NVD link : CVE-2026-46232

Mitre link : CVE-2026-46232

CVE.ORG link : CVE-2026-46232


JSON object : View

Products Affected

linux

  • linux_kernel