---
id: CVE-2026-98206
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Input: cyttsp5 - clamp the HID report size before memcpy

  The size field comes from the device and is used as the memcpy()
  length into response_buf, which is CY_MAX_INP…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  Input: cyttsp5 - clamp the HID report size before memcpy

  The size field comes from the device and is used as the memcpy()
  length into response_buf, which is CY_MAX_INP…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 5b0c03e24a061f9c9e8b28fa157b80990c559a37 <
    b172c69e67bc71f71f6e3d8b3258b3dec29e42c6
  - >-
    Linux >= 5b0c03e24a061f9c9e8b28fa157b80990c559a37 <
    d41a80d852f2948c6d388c520e76c0a72897f003
  - >-
    Linux >= 5b0c03e24a061f9c9e8b28fa157b80990c559a37 <
    9eb261092d4c967679fa351b7190c6d9082b07c5
  - >-
    Linux >= 5b0c03e24a061f9c9e8b28fa157b80990c559a37 <
    495955feb57750de4a641da13d7e51fb4d0a9764
  - >-
    Linux >= 5b0c03e24a061f9c9e8b28fa157b80990c559a37 <
    85f080fb87ed5cd3e46121be677f52c82f26a0ab
  - Linux 6.2
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:06.710'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98206'
references:
  - url: 'https://git.kernel.org/stable/c/495955feb57750de4a641da13d7e51fb4d0a9764'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/85f080fb87ed5cd3e46121be677f52c82f26a0ab'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/9eb261092d4c967679fa351b7190c6d9082b07c5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b172c69e67bc71f71f6e3d8b3258b3dec29e42c6'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/d41a80d852f2948c6d388c520e76c0a72897f003'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.445Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

Input: cyttsp5 - clamp the HID report size before memcpy

The size field comes from the device and is used as the memcpy()
length into response_buf, which is CY_MAX_INPUT bytes.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
