{
  "affected": [
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:12",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.176-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:13",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.12.94-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "ecosystem_specific": {
        "urgency": "not yet assigned"
      },
      "package": {
        "ecosystem": "Debian:14",
        "name": "linux"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.12-1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "details": "In the Linux kernel, the following vulnerability has been resolved:  Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size  nexio_read_data() pulls data_len and x_len from a packed __be16 header in the device's interrupt packet and then walks packet-\u003edata[0..x_len) and packet-\u003edata[x_len..data_len) comparing each byte against a threshold.  Both fields are 16-bit on the wire (max 65535).  The existing adjustments shave at most 0x100 / 0x80 off, so the loop bound can still reach roughly 0xfeff.  The URB transfer buffer for NEXIO is rept_size (1024) bytes from usb_alloc_coherent(), with the first 7 occupied by the packed header — so packet-\u003edata[] has 1017 valid bytes.  read_data() callbacks are not given urb-\u003eactual_length, and nothing else bounds the walk.  A device that lies about its length can get a ~64 KiB out-of-bounds read past the coherent DMA allocation.  The first index whose byte exceeds NEXIO_THRESHOLD lands in begin_x / begin_y and from there into the reported touch coordinates, so adjacent kernel memory contents leak to userspace as ABS_X / ABS_Y events.  Far enough out, the read can also hit an unmapped page and fault.  Fix this all by clamping data_len to the buffer's data[] capacity and x_len to data_len.",
  "id": "DEBIAN-CVE-2026-64014",
  "modified": "2026-09-14T16:47:34.325558142Z",
  "published": "2026-07-19T16:17:41.320Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://security-tracker.debian.org/tracker/CVE-2026-64014"
    }
  ],
  "upstream": [
    "CVE-2026-64014"
  ]
}