CVE-2026-80570

HIGHPre-NVD 7.87.8
EchelonGraph scoreHIGH confidence

Score 7.8 from GitHub Security Advisory (severity: HIGH) published 2026-08-27. a secondary CVSS source baseline 7.8; sources differ by 0.0.

Triggered by: GitHub Security Advisory CVSS
Sources: epss, ghsa, secondary
Trending — 5 sources updated this week
7.8EG
EchelonGraph verdictPlan a fixSerious severity, but no confirmed exploitation yet.
  • High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS PROB: 0%CVSS: 7.8Exploit: None knownExposed: 0

No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.

In the Linux kernel, the following vulnerability has been resolved:

Input: synaptics-rmi4 - zero report size on F54 work error

In rmi_f54_work(), if an error occurs during report request or command verification, the code jumped directly to the 'error' label, bypassing the 'abort' label where f54->report_size was normally zeroed out.

This left f54->report_size containing its previous successful payload size. If a user then altered the V4L2 format to a smaller size, and a subsequent run failed, rmi_f54_buffer_queue() would copy the stale, larger payload size into the shrunken V4L2 buffer, causing a heap buffer overflow.

Fix this by merging the 'abort' and 'error' labels into a single 'out' exit path, and ensuring that f54->report_size is always set to 0 on failure by checking for error and zeroing the local report_size first.

CVSS v3
7.8
EG Score
7.8(high)
EG Risk
40(Track)
EG Risk 40/100SSVC: Track

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity78% × 45%
Exploitation0% × 40%
Automatability30% × 15%
Action: Routine — remediate on your standard cadence.
EPSS PROB
0%
EPSS %ILE
3%
KEV
Not listed

Published

August 26, 2026

Last Modified

August 27, 2026

Advisory Details (8)

Auto-updated Aug 27, 2026
No patch confirmed yet.
generic

Input: synaptics-rmi4 - zero report size on F54 work error - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/dc76c3c8e8ad09362b8c1561f3928288c15cba2e
generic

Input: synaptics-rmi4 - zero report size on F54 work error - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/c6cfda79f26c69e97db9805808c3b44d02227b4b
generic

Input: synaptics-rmi4 - zero report size on F54 work error - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/c669c64ab71afa7b467c4d7e18f6a05e96b97a1f
generic

Input: synaptics-rmi4 - zero report size on F54 work error - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/b28593a05afdd812b590e1045b5bd862a5869225
generic

Input: synaptics-rmi4 - zero report size on F54 work error - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/88c8174d72900d77fbdf2f527d54b6ff2da876a8
generic

Input: synaptics-rmi4 - zero report size on F54 work error - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/79521ed3cc9ea48476666ccacf45ecd6954b29a4
generic

Input: synaptics-rmi4 - zero report size on F54 work error - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/77749685e55da19b187df215b5da4080842ca5c7
generic

Input: synaptics-rmi4 - zero report size on F54 work error - kernel/git/stable/linux.git - Linux kernel stable tree

https://git.kernel.org/stable/c/62079c17ec07d64362bec367ee7a525b0dbf6bf9

Vendor Advisories for CVE-2026-80570(1)

These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.

Data Freshness Timeline

(refreshed 17× in last 7d / 17× in last 30d)

Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.

  1. 2026-08-30 05:04 UTCEG score recompute
  2. 2026-08-30 05:03 UTCGHSA enrichment
  3. 2026-08-30 01:22 UTCEPSS rescore
  4. 2026-08-29 17:22 UTCGHSA enrichment
  5. 2026-08-29 05:09 UTCEG score recompute
  6. 2026-08-29 05:09 UTCGHSA enrichment
  7. 2026-08-28 21:42 UTCEPSS rescore
  8. 2026-08-28 17:27 UTCGHSA enrichment
  9. 2026-08-28 05:44 UTCGHSA enrichment
  10. 2026-08-27 18:04 UTCEG score recompute
  11. 2026-08-27 18:04 UTCGHSA enrichment
  12. 2026-08-27 14:25 UTCEPSS rescore
  13. 2026-08-27 06:18 UTCEG score recompute 7.80
  14. 2026-08-27 06:11 UTCMITRE cvelistV5CVSS v3 → 7.8 · severity → HIGH
  15. 2026-08-26 15:43 UTCNVD update
  16. 2026-08-26 14:42 UTCEG score recompute
  17. 2026-08-26 14:41 UTCMITRE cvelistV5first tracked

Frequently asked(5)

What is CVE-2026-80570?
CVE-2026-80570 is a high vulnerability published on August 26, 2026. In the Linux kernel, the following vulnerability has been resolved: Input: synaptics-rmi4 - zero report size on F54 work error In rmif54work(), if an error occurs during report request or command verification, the code jumped directly to the 'error' label, bypassing the 'abort' label where…
When was CVE-2026-80570 disclosed?
CVE-2026-80570 was first published in the National Vulnerability Database on August 26, 2026, with the most recent update on August 27, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2026-80570 actively exploited?
CVE-2026-80570 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 0% probability of exploitation in the next 30 days, which ranks it in the top 96.8% of all scored CVEs.
What is the CVSS score of CVE-2026-80570?
CVE-2026-80570 has a CVSS v3 base score of 7.8 (NVD).
How do I remediate CVE-2026-80570?
Patch to the fixed version published by the affected vendor. Where vendor advisories exist for CVE-2026-80570, EchelonGraph cross-links them in the Vendor Advisories panel below — those typically contain the canonical remediation steps, fixed version numbers, and any vendor-specific mitigations.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2026-80570

Explore →

Is Your Infrastructure Affected by CVE-2026-80570?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.