PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-19576 zephyrproject CVE debrief

A stack out-of-bounds write vulnerability exists in the Goodix GT911 touch controller driver within the Zephyr operating system. The issue arises from an unvalidated device-reported touch point count, which can lead to up to 112 bytes of peer-supplied data being written past the end of a stack array. This vulnerability can be triggered by a controller that reports more points than the array holds, and it requires control of, or the ability to substitute, the I2C touch controller. Such a scenario is plausible on supported boards where the GT9xx panel is a pluggable display module or shield rather than an on-PCB part.

Vendor
zephyrproject
Product
zephyr
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders responsible for systems using the Zephyr operating system with the Goodix GT911 touch controller should assess their exposure to this vulnerability. This includes developers and administrators of systems with pluggable display modules or shields, as these are potential attack vectors.

Why it matters

This vulnerability requires attention from defenders responsible for systems using the Zephyr operating system with the Goodix GT911 touch controller. The vulnerability can be triggered by a controller that reports more points than the array holds, and it requires control of, or the ability to substitute, the I2C touch controller. Defenders should prioritize verifying the touch controller's configuration and validating the device-reported touch point count to prevent potential stack corruption.

  • Potential stack corruption leading to system instability or crashes.
  • Possible elevation of privileges or arbitrary code execution.
  • Increased risk of denial-of-service (DoS) attacks.
  • Need for verification of touch controller configuration and validation of device-reported touch point count.

Technical summary

The Goodix GT911 touch controller driver in the Zephyr operating system is vulnerable to a stack out-of-bounds write. The driver reads the touch point count from the controller's status register and uses it directly as a loop bound for filling a stack array. If the controller reports more points than the array holds, up to 112 bytes of peer-supplied data can be written past the end of the array, potentially causing stack corruption.

Defensive priority

Defenders should prioritize verifying the touch controller's configuration and validating the device-reported touch point count to prevent potential stack corruption. They should also assess the exposure of their systems, particularly those with pluggable display modules or shields, and consider applying patches or workarounds provided by the vendor.

Recommended defensive actions

  • Verify the touch controller's configuration to ensure it is properly set up and validated.
  • Validate the device-reported touch point count to prevent potential stack corruption.
  • Assess the exposure of systems, particularly those with pluggable display modules or shields.
  • Apply patches or workarounds provided by the vendor to address the vulnerability.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability is caused by the lack of validation of the touch point count reported by the device. The Goodix GT911 touch controller driver reads the touch point count from the controller's status register and uses it directly as a loop bound for filling a stack array. This can lead to a stack out-of-bounds write if the controller reports more points than the array holds.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-19576 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-19576

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-19576 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19576

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.