Impact
The atmel_mxt_ts driver performs a boundary check on configuration file data but incorrectly allows the last byte of an object to be processed, resulting in a one‑byte write into adjacent kernel memory. This unchecked write can corrupt kernel data structures or control information, providing a potential local privilege escalation or system instability, as the flaw is a classic out‑of‑bounds write classified as CWE‑787.
Affected Systems
The flaw affects Linux kernels that include the atmel_mxt_ts driver prior to the patch. All distributions shipping that kernel revision are impacted; however, the database does not specify exact version numbers. Administrators should inspect the atmel_mxt_ts driver version in their kernel source and apply the recent patch that implements the correct >= check.
Risk and Exploitability
The EPSS score is reported as less than 1% and the vulnerability is not in the CISA KEV catalog, indicating a low likelihood of exploitation in the wild. Based on the description, it is inferred that the attack vector involves a local user who can supply a malicious configuration file to the driver, potentially allowing that user to corrupt kernel memory. While no active exploits are documented, the potential impact on system integrity and stability makes timely remediation prudent.
OpenCVE Enrichment
Ubuntu USN