CVE-2026-98206
Published Oct 6, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: Input: cyttsp5 - clamp the HID report size before memcpy The size field comes from the device and is used as the memcpy() length into response_buf, which is CY_MAX_INPUT bytes.
Is your site exposed to CVE-2026-98206?
Run a free security scan — no signup, results in seconds.
EPSS — Exploit Prediction
0.0018
Probability of exploitation
0.06%
Percentile rank
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
References
Other References
https://git.kernel.org/stable/c/495955feb57750de4a641da13d7e51fb4d0a9764
https://git.kernel.org/stable/c/85f080fb87ed5cd3e46121be677f52c82f26a0ab
https://git.kernel.org/stable/c/9eb261092d4c967679fa351b7190c6d9082b07c5
https://git.kernel.org/stable/c/b172c69e67bc71f71f6e3d8b3258b3dec29e42c6
https://git.kernel.org/stable/c/d41a80d852f2948c6d388c520e76c0a72897f003
Frequently Asked Questions
What is CVE-2026-98206? +
In the Linux kernel, the following vulnerability has been resolved:
Input: cyttsp5 - clamp the HID report size before memcpy
The size field comes from the device and is used as the memcpy()
length into response_buf, which is CY_MAX_INPUT bytes.
How do I check if I'm vulnerable to CVE-2026-98206? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.