Sceawere

Vulnerability Detail

CVE-2026-19576UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GT9xx Driver Stack Buffer Overflow

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.8
Creation Date
4h ago
Vendor
zephyrproject
Product
zephyr
Attack Type
bounds
Vector String
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Goodix GT9xx input driver in drivers/input/input_gt911.c reads the touch point count from the controller's status register and masks it with GT911_TOUCH_POINTS_MSK (0x0F), yielding a value of 0..15. In gt911_process() that value is used directly as the loop bound for filling point_reg[], a stack array sized to CONFIG_INPUT_GT911_MAX_TOUCH_POINTS, whose Kconfig range is 1..5 with a default of 1. No other check constrains the count; the driver relied only on a comment asserting that the controller had been programmed at init to report no more points than configured. Each loop iteration issues an I2C read of eight bytes straight into point_reg[i], so a controller that reports more points than the array holds causes up to 112 bytes of peer-supplied data to be written past the end of the array, over the stack frame of gt911_process() in the system workqueue thread. Two further loops then read out of bounds from the same array. Triggering it requires control of, or the ability to substitute, the I2C touch controller — plausible on the many supported boards where the GT9xx panel is a pluggable display module or shield rather than an on-PCB part; a spoofed device need only answer the init probes with a supported product ID and a checksum-valid config blob. The same overflow can also occur non-adversarially, with a GT9271-class panel that ignores the driver's touch-count programming and reports up to ten points, or with bus corruption of the single status byte. The impact is an out-of-bounds stack write with fully attacker-chosen content executing at kernel privilege, i.e. potential control-flow hijack on the host MCU, in addition to out-of-bounds reads and crashes. The attack vector is physical/local hardware access only; there is no network, USB, or syscall path to the defect. The fix clamps the reported count with min() against CONFIG_INPUT_GT911_MAX_TOUCH_POINTS before any array indexing.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.8",
  "pubDate": "2026-10-11T18:16:58.300Z",
  "pubdate": "2026-10-11T18:16:58.300Z",
  "executiveSummary": "A critical stack-based buffer overflow vulnerability exists in the Goodix GT9xx input driver (drivers/input/input_gt911.c).\nThe vulnerability occurs because the driver fails to validate the touch point count reported by the I2C controller against the allocated buffer size.\nAn attacker with physical access to the I2C bus can inject malicious data to trigger memory corruption, potentially leading to arbitrary code execution with kernel-level privileges.\nThe flaw affects systems using the GT9xx input driver where the touch controller is reachable via I2C, particularly in modular hardware designs where the touch panel is a pluggable component.\nNon-adversarial triggers, such as bus corruption or incompatible controller behavior, can also lead to system instability and kernel panics.\nExploitation requires physical or local access to the target hardware to manipulate or spoof I2C bus communications.\nThis vulnerability highlights the risks associated with trusting hardware-provided configuration values without performing strict bounds checking.",
  "technicalDetails": "The vulnerability originates in the gt911_process() function within drivers/input/input_gt911.c, which processes input data received from the GT9xx touch controller.\nThe driver reads a status register from the I2C controller to determine the number of active touch points. This value is masked with GT911_TOUCH_POINTS_MSK (0x0F), allowing for a reported count between 0 and 15.\nThe root cause is an insufficient validation of this count before it is used as a loop bound to write data into the point_reg[] stack array. This array is sized according to the Kconfig variable CONFIG_INPUT_GT911_MAX_TOUCH_POINTS, which has a default value of 1 and a maximum allowed range of 5.\nBecause there is no secondary check to ensure the hardware-reported touch count does not exceed the array size, a malicious or malfunctioning controller can report up to 15 points. In each iteration, the driver performs an I2C read operation that writes 8 bytes of data directly into the stack-allocated point_reg[] buffer.\nIf the reported count exceeds the defined CONFIG_INPUT_GT911_MAX_TOUCH_POINTS, the driver performs out-of-bounds (OOB) writes, overwriting sensitive data on the kernel stack, including function return addresses or local variables within the system workqueue thread context.\nFollowing the initial buffer overflow, two additional loops within the same function perform OOB reads from the corrupted array, potentially leaking stack data back to the system or causing further instability.\nThe attack vector involves a malicious device spoofing a valid Goodix controller. The attacker must provide a valid product ID and satisfy checksum requirements during the initialization probes. Once the spoofed device is accepted, the attacker controls the values written during the I2C transfers, allowing for precise memory corruption.\nSuccessful exploitation results in control-flow hijacking, enabling an attacker to execute arbitrary code with kernel privileges. As the driver runs within a system workqueue, the payload executes with the privileges of the kernel, granting total control over the host MCU. This vulnerability is strictly local; it cannot be triggered via network or user-space syscall interfaces."
}
CVE-2026-19576: GT9xx Driver Stack Buffer Overflow (MEDIUM Severity, CVSS: 6.8) | Sceawere