CVE-2026-98206

Linux

Published 6 Oct 2026 · updated 6 Oct 2026 · Received

— Not scored yet

Description

In the Linux kernel, the following vulnerability has been resolved: Input: cyttsp5 - clamp the HID report size before memcpy The size field comes from the device and is used as the memcpy() length into response_buf, which is CY_MAX_INPUT bytes.

References