CVE-2026-80567

Summary

In the Linux kernel, the following vulnerability has been resolved:

Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue

Previously, rmi_f54_buffer_queue() waited for the worker thread to finish but ignored whether it succeeded. If the worker failed (e.g., due to a timeout or register read failure), the queue thread would silently return success, delivering stale or uninitialized memory to userspace.

Add a 'report_error' field to struct f54_data to store the worker's exit status. Check this field in rmi_f54_buffer_queue() after the worker finishes, and mark the buffer as VB2_BUF_STATE_ERROR if an error occurred.

Affected Software

VendorProductVersion RangeStatus
LinuxLinux3a762dbd5347514c3cb2ac756a92a3d1c7646a2d < 305c24ee25b6e08ac9f4c5f697e823cc638c38daaffected
LinuxLinux3a762dbd5347514c3cb2ac756a92a3d1c7646a2d < 7d33b752e0df385b285492b74699fc73b6becdfbaffected
LinuxLinux3a762dbd5347514c3cb2ac756a92a3d1c7646a2d < be56730b547737151f24357d832b04aaa93755d5affected
LinuxLinux3a762dbd5347514c3cb2ac756a92a3d1c7646a2d < 2b0403fb7e28f65883cd03814b62c9aa9bc7f04daffected
LinuxLinux3a762dbd5347514c3cb2ac756a92a3d1c7646a2d < 6741a8c21d98088b7f2d9f4f86a706d311ce34a2affected
LinuxLinux3a762dbd5347514c3cb2ac756a92a3d1c7646a2d < 70f9aad3943559af6f32cb303744f35c05ce9cf1affected
LinuxLinux3a762dbd5347514c3cb2ac756a92a3d1c7646a2d < 9bbd3682f8a3e064271547133c37fcb17668d860affected
LinuxLinux3a762dbd5347514c3cb2ac756a92a3d1c7646a2d < 8786d74bf50e6797b6f655eb381ef6b25451161faffected
LinuxLinux4.9affected
LinuxLinux0 < 4.9unaffected
LinuxLinux5.10.266 <= 5.10.*unaffected
LinuxLinux5.15.217 <= 5.15.*unaffected
LinuxLinux6.1.184 <= 6.1.*unaffected
LinuxLinux6.6.153 <= 6.6.*unaffected
LinuxLinux6.12.105 <= 6.12.*unaffected
LinuxLinux6.18.46 <= 6.18.*unaffected
LinuxLinux7.1.10 <= 7.1.*unaffected
LinuxLinux7.2 <= *unaffected

Weaknesses

References