---
cve: "CVE-2026-64270"
severity: "LOW"
cvss: 3.1
epss: "0.2%"
vendor: "Linux"
kev: false
exploited: false
published: "2026-07-25 08:49:17"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-21T11:00:39+02:00"
---

# CVE-2026-64270

> 3.1 LOW

## Beschreibung

In the Linux kernel, the following vulnerability has been resolved:

Input: mms114 - reject an oversized device packet size

mms114_interrupt() reads a packet of touch data from the device into a
fixed-size on-stack buffer

	struct mms114_touch touch[MMS114_MAX_TOUCH];

which holds MMS114_MAX_TOUCH (10) events of MMS114_EVENT_SIZE (8) bytes,
i.e. 80 bytes. The length of the I2C read into it is taken verbatim from
the device:

	packet_size = mms114_read_reg(data, MMS114_PACKET_SIZE);
	if (packet_size

## Patch verfügbar (OSV)

- Kernel ≥ 5.10.266
- Kernel ≥ 5.15.217
- Kernel ≥ 6.1.184
- Kernel ≥ 6.6.145
- Kernel ≥ 6.12.96
- Kernel ≥ 6.18.39
- Kernel ≥ 7.1.4

## Referenzen

- <https://git.kernel.org/stable/c/040843281eebfa110d08fd7fb083fe6cb55cea14>
- <https://git.kernel.org/stable/c/39b12daf1adb80f9595fdfe584961deb80860cbb>
- <https://git.kernel.org/stable/c/d99ba93c35ff2d5276e9c2632967481bd53a79d0>
- <https://git.kernel.org/stable/c/5d2ea15ba03bf17ed143ff1a0995a4206edc3fb6>
- <https://git.kernel.org/stable/c/b78150729762d47c14fe29a2582bdca5568e62b8>
- <https://git.kernel.org/stable/c/8301c335305344d4da4ab9442b6a399dacfe5b8d>
- <https://git.kernel.org/stable/c/f3d5e77b27fded71dcb97f409262bf0abba0410e>
- <https://git.kernel.org/stable/c/66725039f7090afe14c31bd259e2059a68f04023>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-64270) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
