{"id":"CVE-2026-80754","summary":"Input: synaptics-rmi4 - fix F55 transmitter electrode count typo","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: synaptics-rmi4 - fix F55 transmitter electrode count typo\n\nDuring F55 sensor detection, the transmitter (TX) electrode count was\nincorrectly assigned the value of the receiver (RX) electrode count\ndue to copy-paste typos.\n\nThis incorrect value was then propagated to the driver data and used\nby F54 to determine the diagnostics report size. On devices with more\nRX than TX electrodes, this inflated the perceived TX count, leading\nto incorrect report size calculations and potential out-of-bounds\nbuffer accesses.\n\nFix the typos by correctly assigning the TX electrode counts.","modified":"2026-09-05T03:48:34.721161861Z","published":"2026-09-03T08:26:33.180Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80754.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/0739c65e799d4a93fe573ed23255a71fcfcc5438"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6058f0fea10f3caf63a435677358d1b8e9325114"},{"type":"WEB","url":"https://git.kernel.org/stable/c/6484e00d6778fdf2209cd75940bc3902b276457f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9759502f5cd71805923457f183ae5b9533e20c7b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/9b184c8337c6e12df129399007735a7fbcbbcb7b"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a6d9646e77da7cab2dff7043a8e9f75e23b836bc"},{"type":"WEB","url":"https://git.kernel.org/stable/c/a81cafe3c3c2f8494063385a7b0ea7ff407bf19f"},{"type":"WEB","url":"https://git.kernel.org/stable/c/db4e20265ebda729610ca5cf45ca9437462c3f36"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/80xxx/CVE-2026-80754.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-80754"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"6adba43fd222ea362c36296d1a6897c2e28fdc8e"},{"fixed":"6484e00d6778fdf2209cd75940bc3902b276457f"},{"fixed":"db4e20265ebda729610ca5cf45ca9437462c3f36"},{"fixed":"a6d9646e77da7cab2dff7043a8e9f75e23b836bc"},{"fixed":"0739c65e799d4a93fe573ed23255a71fcfcc5438"},{"fixed":"9759502f5cd71805923457f183ae5b9533e20c7b"},{"fixed":"9b184c8337c6e12df129399007735a7fbcbbcb7b"},{"fixed":"a81cafe3c3c2f8494063385a7b0ea7ff407bf19f"},{"fixed":"6058f0fea10f3caf63a435677358d1b8e9325114"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80754.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.10.0"},{"fixed":"5.10.266"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.11.0"},{"fixed":"5.15.217"}]},{"type":"ECOSYSTEM","events":[{"introduced":"5.16.0"},{"fixed":"6.1.184"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.2.0"},{"fixed":"6.6.153"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.7.0"},{"fixed":"6.12.105"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.13.0"},{"fixed":"6.18.46"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.1.10"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-80754.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}