Impact
The Goodix GT9xx driver in Zephyr RTOS allows a touch controller that reports a higher number of touch points than the driver expects to overwrite stack memory. This is a typical CWE‑787: Out‑of‑Bounds Write. By supplying a touch count of up to fifteen, the driver writes up to 112 bytes beyond a stack array that was allocated for a configuration‑defined maximum of one to five points. This can corrupt the return address of the workqueue thread and lead to arbitrary code execution at kernel level. The flaw also causes out‑of‑bounds reads and can crash the system.
Affected Systems
The vulnerability affects Zephyr Project’s Zephyr RTOS, specifically the input_gt911.c driver for the Goodix GT9xx touch controller. The affected product is the driver module; version information is not provided, but any build that includes the unpatched driver is susceptible.
Risk and Exploitability
The CVSS score is 6.8, indicating a moderate severity. No EPSS score is available, so the current exploitation probability cannot be quantified. The flaw is not listed in the CISA KEV catalog. An attacker must have physical or local hardware access to the I2C touch controller to trigger the overflow, which is plausible on boards where the panel is a plug‑in module rather than an on‑board component. The exploit requires the device to supply a touch count above the configured maximum; the attack vector is purely local hardware control, with no network or software interface available for remote exploitation.
OpenCVE Enrichment