Description
The Goodix GT9xx input driver in drivers/input/input_gt911.c reads the touch point count from the controller's status register and masks it with GT911_TOUCH_POINTS_MSK (0x0F), yielding a value of 0..15. In gt911_process() that value is used directly as the loop bound for filling point_reg[], a stack array sized to CONFIG_INPUT_GT911_MAX_TOUCH_POINTS, whose Kconfig range is 1..5 with a default of 1. No other check constrains the count; the driver relied only on a comment asserting that the controller had been programmed at init to report no more points than configured.

Each loop iteration issues an I2C read of eight bytes straight into point_reg[i], so a controller that reports more points than the array holds causes up to 112 bytes of peer-supplied data to be written past the end of the array, over the stack frame of gt911_process() in the system workqueue thread. Two further loops then read out of bounds from the same array. Triggering it requires control of, or the ability to substitute, the I2C touch controller — plausible on the many supported boards where the GT9xx panel is a pluggable display module or shield rather than an on-PCB part; a spoofed device need only answer the init probes with a supported product ID and a checksum-valid config blob. The same overflow can also occur non-adversarially, with a GT9271-class panel that ignores the driver's touch-count programming and reports up to ten points, or with bus corruption of the single status byte.

The impact is an out-of-bounds stack write with fully attacker-chosen content executing at kernel privilege, i.e. potential control-flow hijack on the host MCU, in addition to out-of-bounds reads and crashes. The attack vector is physical/local hardware access only; there is no network, USB, or syscall path to the defect. The fix clamps the reported count with min() against CONFIG_INPUT_GT911_MAX_TOUCH_POINTS before any array indexing.
Published: 2026-10-11
Score: 6.8 Medium
EPSS: n/a
KEV: No
Impact: Out-of-Bounds Stack Write with Kernel Privilege Execution
Action: Apply Patch
AI Analysis

Impact

The Goodix GT9xx driver in Zephyr RTOS allows a touch controller that reports a higher number of touch points than the driver expects to overwrite stack memory. This is a typical CWE‑787: Out‑of‑Bounds Write. By supplying a touch count of up to fifteen, the driver writes up to 112 bytes beyond a stack array that was allocated for a configuration‑defined maximum of one to five points. This can corrupt the return address of the workqueue thread and lead to arbitrary code execution at kernel level. The flaw also causes out‑of‑bounds reads and can crash the system.

Affected Systems

The vulnerability affects Zephyr Project’s Zephyr RTOS, specifically the input_gt911.c driver for the Goodix GT9xx touch controller. The affected product is the driver module; version information is not provided, but any build that includes the unpatched driver is susceptible.

Risk and Exploitability

The CVSS score is 6.8, indicating a moderate severity. No EPSS score is available, so the current exploitation probability cannot be quantified. The flaw is not listed in the CISA KEV catalog. An attacker must have physical or local hardware access to the I2C touch controller to trigger the overflow, which is plausible on boards where the panel is a plug‑in module rather than an on‑board component. The exploit requires the device to supply a touch count above the configured maximum; the attack vector is purely local hardware control, with no network or software interface available for remote exploitation.

Generated by OpenCVE AI on October 11, 2026 at 18:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the Zephyr patch that clamps the reported touch point count to the configured maximum (see commit 42b52d57).
  • Reconfigure CONFIG_GT911_MAX_TOUCH_POINTS so that it matches the actual panel capacity and is at least as low as the maximum points the controller will report.
  • Secure the I2C interface to the GT911 controller so that only trusted firmware can communicate with it, mitigating the risk of a spoofed or tampered controller.

Generated by OpenCVE AI on October 11, 2026 at 18:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Zephyrproject
Zephyrproject zephyr
Vendors & Products Zephyrproject
Zephyrproject zephyr

Sun, 11 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Description The Goodix GT9xx input driver in drivers/input/input_gt911.c reads the touch point count from the controller's status register and masks it with GT911_TOUCH_POINTS_MSK (0x0F), yielding a value of 0..15. In gt911_process() that value is used directly as the loop bound for filling point_reg[], a stack array sized to CONFIG_INPUT_GT911_MAX_TOUCH_POINTS, whose Kconfig range is 1..5 with a default of 1. No other check constrains the count; the driver relied only on a comment asserting that the controller had been programmed at init to report no more points than configured. Each loop iteration issues an I2C read of eight bytes straight into point_reg[i], so a controller that reports more points than the array holds causes up to 112 bytes of peer-supplied data to be written past the end of the array, over the stack frame of gt911_process() in the system workqueue thread. Two further loops then read out of bounds from the same array. Triggering it requires control of, or the ability to substitute, the I2C touch controller — plausible on the many supported boards where the GT9xx panel is a pluggable display module or shield rather than an on-PCB part; a spoofed device need only answer the init probes with a supported product ID and a checksum-valid config blob. The same overflow can also occur non-adversarially, with a GT9271-class panel that ignores the driver's touch-count programming and reports up to ten points, or with bus corruption of the single status byte. The impact is an out-of-bounds stack write with fully attacker-chosen content executing at kernel privilege, i.e. potential control-flow hijack on the host MCU, in addition to out-of-bounds reads and crashes. The attack vector is physical/local hardware access only; there is no network, USB, or syscall path to the defect. The fix clamps the reported count with min() against CONFIG_INPUT_GT911_MAX_TOUCH_POINTS before any array indexing.
Title Stack out-of-bounds write in the Goodix GT911 touch controller driver from an unvalidated device-reported touch point count
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Zephyrproject Zephyr
cve-icon MITRE

Status: PUBLISHED

Assigner: zephyr

Published:

Updated: 2026-10-11T17:14:53.339Z

Reserved: 2026-08-11T19:56:48.396Z

Link: CVE-2026-19576

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T18:16:58.300

Modified: 2026-10-11T18:16:58.300

Link: CVE-2026-19576

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T19:00:14Z

Weaknesses