PatchSiren cyber security CVE debrief
CVE-2026-19576 zephyrproject CVE debrief
A stack out-of-bounds write vulnerability exists in the Goodix GT911 touch controller driver within the Zephyr operating system. The issue arises from an unvalidated device-reported touch point count, which can lead to up to 112 bytes of peer-supplied data being written past the end of a stack array. This vulnerability can be triggered by a controller that reports more points than the array holds, and it requires control of, or the ability to substitute, the I2C touch controller. Such a scenario is plausible on supported boards where the GT9xx panel is a pluggable display module or shield rather than an on-PCB part.
- Vendor
- zephyrproject
- Product
- zephyr
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for systems using the Zephyr operating system with the Goodix GT911 touch controller should assess their exposure to this vulnerability. This includes developers and administrators of systems with pluggable display modules or shields, as these are potential attack vectors.
Why it matters
This vulnerability requires attention from defenders responsible for systems using the Zephyr operating system with the Goodix GT911 touch controller. The vulnerability can be triggered by a controller that reports more points than the array holds, and it requires control of, or the ability to substitute, the I2C touch controller. Defenders should prioritize verifying the touch controller's configuration and validating the device-reported touch point count to prevent potential stack corruption.
- Potential stack corruption leading to system instability or crashes.
- Possible elevation of privileges or arbitrary code execution.
- Increased risk of denial-of-service (DoS) attacks.
- Need for verification of touch controller configuration and validation of device-reported touch point count.
Technical summary
The Goodix GT911 touch controller driver in the Zephyr operating system is vulnerable to a stack out-of-bounds write. The driver reads the touch point count from the controller's status register and uses it directly as a loop bound for filling a stack array. If the controller reports more points than the array holds, up to 112 bytes of peer-supplied data can be written past the end of the array, potentially causing stack corruption.
Defensive priority
Defenders should prioritize verifying the touch controller's configuration and validating the device-reported touch point count to prevent potential stack corruption. They should also assess the exposure of their systems, particularly those with pluggable display modules or shields, and consider applying patches or workarounds provided by the vendor.
Recommended defensive actions
- Verify the touch controller's configuration to ensure it is properly set up and validated.
- Validate the device-reported touch point count to prevent potential stack corruption.
- Assess the exposure of systems, particularly those with pluggable display modules or shields.
- Apply patches or workarounds provided by the vendor to address the vulnerability.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The vulnerability is caused by the lack of validation of the touch point count reported by the device. The Goodix GT911 touch controller driver reads the touch point count from the controller's status register and uses it directly as a loop bound for filling a stack array. This can lead to a stack out-of-bounds write if the controller reports more points than the array holds.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-19576 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-19576
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-19576 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-19576
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Stack out-of-bounds write in the Goodix GT911 touch controller driver from an unvalidated device
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/19xxx/CVE-2026-19576.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/zephyrproject-rtos/zephyr/commit/42b52d571eb2113012c135276693042fd372fdea
Supplemental source - patch
-
Source reference
Unverified legacy reference
URL: https://github.com/zephyrproject-rtos/zephyr/security/advisories/GHSA-p7qh-fvwx-f7vr
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.