{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-19576", "assignerOrgId": "e2e69745-5e70-4e92-8431-deb5529a81ad", "state": "PUBLISHED", "assignerShortName": "zephyr", "dateReserved": "2026-08-11T19:56:48.396Z", "datePublished": "2026-10-11T17:14:53.339Z", "dateUpdated": "2026-10-11T17:14:53.339Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "e2e69745-5e70-4e92-8431-deb5529a81ad", "shortName": "zephyr", "dateUpdated": "2026-10-11T17:14:53.339Z" }, "title": "Stack out-of-bounds write in the Goodix GT911 touch controller driver from an unvalidated device-reported touch point count", "descriptions": [ { "lang": "en", "value": "The Goodix GT9xx input driver in drivers/input/input_gt911.c reads the touch point count from the controller's status register and masks it with GT911_TOUCH_POINTS_MSK (0x0F), yielding a value of 0..15. In gt911_process() that value is used directly as the loop bound for filling point_reg[], a stack array sized to CONFIG_INPUT_GT911_MAX_TOUCH_POINTS, whose Kconfig range is 1..5 with a default of 1. No other check constrains the count; the driver relied only on a comment asserting that the controller had been programmed at init to report no more points than configured.\n\nEach loop iteration issues an I2C read of eight bytes straight into point_reg[i], so a controller that reports more points than the array holds causes up to 112 bytes of peer-supplied data to be written past the end of the array, over the stack frame of gt911_process() in the system workqueue thread. Two further loops then read out of bounds from the same array. Triggering it requires control of, or the ability to substitute, the I2C touch controller — plausible on the many supported boards where the GT9xx panel is a pluggable display module or shield rather than an on-PCB part; a spoofed device need only answer the init probes with a supported product ID and a checksum-valid config blob. The same overflow can also occur non-adversarially, with a GT9271-class panel that ignores the driver's touch-count programming and reports up to ten points, or with bus corruption of the single status byte.\n\nThe impact is an out-of-bounds stack write with fully attacker-chosen content executing at kernel privilege, i.e. potential control-flow hijack on the host MCU, in addition to out-of-bounds reads and crashes. The attack vector is physical/local hardware access only; there is no network, USB, or syscall path to the defect. The fix clamps the reported count with min() against CONFIG_INPUT_GT911_MAX_TOUCH_POINTS before any array indexing." } ], "affected": [ { "vendor": "zephyrproject", "product": "zephyr", "collectionURL": "https://github.com/zephyrproject-rtos/zephyr", "packageName": "zephyr", "defaultStatus": "unaffected", "programFiles": [ "drivers/input/input_gt911.c" ], "programRoutines": [ { "name": "gt911_process" } ], "versions": [ { "version": "4.0.0", "status": "affected", "versionType": "semver", "lessThanOrEqual": "4.4.2" } ] } ], "references": [ { "url": "https://github.com/zephyrproject-rtos/zephyr/commit/42b52d571eb2113012c135276693042fd372fdea", "name": "Fix commit", "tags": [ "patch" ] }, { "url": "https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-p7qh-fvwx-f7vr", "name": "GHSA-p7qh-fvwx-f7vr" } ], "metrics": [ { "format": "CVSS", "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 6.8, "baseSeverity": "MEDIUM" } } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "bounds", "cweId": "CWE-787", "type": "CWE" } ] } ], "x_generator": { "engine": "cvelib 1.8.0" } } } }