CVE-2026-80574
Published Aug 26, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet Make finger2 (and also finger1) unsigned, so that if the finger index in the packet is 0 then subtracting 1 creates an array index which overflows above the existing check for FOC_MAX_FINGERS, as the existing comment says it should, instead of writing to state->fingers[-1].
Is your site exposed to CVE-2026-80574?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/063b4c6a6f3fc01bca085c442000c9c100fdbd93
https://git.kernel.org/stable/c/1842e47126816e56d30c4f856f9854fd7831066c
https://git.kernel.org/stable/c/296736076b3fd078742651c719555a488624023a
https://git.kernel.org/stable/c/6f6d5fe29efdf5001bc146fc292e6592cace93eb
https://git.kernel.org/stable/c/81b07470cb2937ceb74b00be88151582a322433b
https://git.kernel.org/stable/c/83c265bfc084d77e2171d4b67362150ab38c935b
https://git.kernel.org/stable/c/bb502d79acb9ac1e0a77fa8bc7b7b4729140b11f
https://git.kernel.org/stable/c/ca92c98b806839c108995b2bbff7061515bdfb53
Frequently Asked Questions
What is CVE-2026-80574? +
In the Linux kernel, the following vulnerability has been resolved:
Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet
Make finger2 (and also finger1) unsigned, so that if the finger index in
the packet is 0 then subtracting 1 creates an array index which overflows
above the existing check for FOC_MAX_FINGERS, as the existing comment says
it should, instead of writing to state->fingers[-1].
How do I check if I'm vulnerable to CVE-2026-80574? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.