PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-64273 Linux CVE debrief

A Linux kernel vulnerability allows an attacker to cause an out-of-bounds read-modify-write past the iforce object by exploiting the iforce driver's force-feedback effect index handling. This issue arises from the driver's failure to properly validate device-reported force-feedback effect indices, potentially leading to local privilege escalation or system compromise. Linux system administrators and users with iforce devices connected should assess exposure and apply patches. The vulnerability exists due to the iforce driver's incorrect handling of force-feedback effect indices, which can be exploited by providing a malicious or counterfeit device.

Vendor
Linux
Product
Unknown
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-25
Original CVE updated
2026-08-17
Advisory published
2026-07-25
Advisory updated
2026-08-17

Who should care

Linux system administrators and users with iforce devices connected should assess exposure and apply patches. This vulnerability in the Linux kernel's iforce driver can be exploited by a local attacker to potentially escalate privileges or compromise the system. Affected operator, platform, vulnerability-management, and security-team impact should be carefully evaluated.

Why it matters

This vulnerability in the Linux kernel's iforce driver can be exploited by a local attacker to potentially escalate privileges or compromise the system. Linux system administrators and users with iforce devices connected should assess exposure and apply patches.

  • Potential local privilege escalation
  • Increased risk of device compromise
  • Need for patch application and system inventory

Technical summary

The iforce driver in the Linux kernel does not properly validate device-reported force-feedback effect indices, allowing for out-of-bounds access to the core_effects array. This can be exploited by a local attacker to potentially escalate privileges or compromise the system. The vulnerability arises from the driver's incorrect handling of force-feedback effect indices, which can be triggered by a malicious or counterfeit device. The issue can be mitigated by applying patches from Linux kernel maintainers and inventorying Linux systems using iforce devices.

Defensive priority

Apply patches to prevent potential local privilege escalation

Recommended defensive actions

  • Apply patches from Linux kernel maintainers
  • Inventory Linux systems using iforce devices
  • Monitor for suspicious device activity
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The vulnerability exists in the Linux kernel's iforce driver, specifically in the handling of force-feedback effect indices. An attacker can exploit this by providing a malicious or counterfeit device that sets or clears a bit at an attacker-chosen offset past the object. The issue is caused by the driver's failure to validate device-reported indices, allowing for out-of-bounds access to the core_effects array.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-64273 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-64273

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-64273 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-64273

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/0e9943d2e4c63496b6ca84bc66fd3c71d40558e2

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/6c0f2901c9d325d4a0574c4237fd507810d225ff

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/70019779325f2bb5f5a4098e91e79c655f50fcef

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/a40250f97c312e000e3616c9074022311a0efbc3

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/b1b79e89bc33e4c682d3df7ae2aadc62b5a0c310

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/c21295616a8a52b9a5f18cd4ca8c73030eda3d4f

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/d10b0507fa0f5b46764b178e3271f9012f2df677

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

  • Source reference

    Unverified legacy reference

    URL: https://git.kernel.org/stable/c/e5fa31f0550b55d80045669ae9080dd5b88abffa

    416baaa9-dc9f-4396-8d5f-8c081fb06d67 - Patch

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.