SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-64366

HIGH · CVSS 8.8 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-25 · Last synced 2026-08-24

CyberRota Analysis

AI-Generated

The vulnerability affects the Linux kernel's handling of Wacom HID devices, specifically within the `wacom_wac_queue_insert()` function, which can lead to a slab-out-of-bounds write due to improper checks on the kfifo buffer size. This flaw allows for potential memory corruption, which could be exploited to execute arbitrary code or cause a denial of service. Organizations using Linux systems with Wacom devices should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-64366
Severity
HIGH
CVSS
8.8
EPSS
0.25%
Linux

Original NVD Description

In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert wacom_wac_queue_insert() calls kfifo_skip() in a loop when the kfifo doesn't have enough space for the incoming report. If the kfifo is empty, kfifo_skip() reads stale data left in the kmalloc'd buffer via __kfifo_peek_n() and interprets it as a record length, advancing fifo->out by that garbage value. This corrupts the internal kfifo state, causing kfifo_unused() to return a value much larger than the actual buffer size, which bypasses __kfifo_in_r()'s guard: if (len + recsize > kfifo_unused(fifo)) return 0; kfifo_copy_in() then performs an out-of-bounds memcpy, writing up to 3842 bytes past the 256-byte buffer. Add a !kfifo_is_empty() condition to the while loop so kfifo_skip() is never called on an empty fifo, and check the return value of kfifo_in() to reject reports that are too large for the fifo.