Answer in brief
CVE-2026-98206 records a Unknown severity vulnerability in Input: cyttsp5 - clamp the HID report size before memcpy. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=5b0c03e24a061f9c9e8b28fa157b80990c559a37 <b172c69e67bc71f71f6e3d8b3258b3dec29e42c6 || >=5b0c03e24a061f9c9e8b28fa157b80990c559a37 <d41a80d852f2948c6d388c520e76c0a72897f003 || >=5b0c03e24a061f9c9e8b28fa157b80990c559a37 <9eb261092d4c967679fa351b7190c6d9082b07c5 || >=5b0c03e24a061f9c9e8b28fa157b80990c559a37 <495955feb57750de4a641da13d7e51fb4d0a9764 || >=5b0c03e24a061f9c9e8b28fa157b80990c559a37 <85f080fb87ed5cd3e46121be677f52c82f26a0ab | b172c69e67bc71f71f6e3d8b3258b3dec29e42c6, d41a80d852f2948c6d388c520e76c0a72897f003, 9eb261092d4c967679fa351b7190c6d9082b07c5, 495955feb57750de4a641da13d7e51fb4d0a9764, 85f080fb87ed5cd3e46121be677f52c82f26a0ab |
| Linux/Linuxgeneric | 6.2 | Not reported |
Published upstream
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 6, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 6, 2026
In the Linux kernel, the following vulnerability has been resolved: Input: cyttsp5 - clamp the HID report size before memcpy The size field comes from the device and is used as the memcpy() length into response_buf, which is CY_MAX_INPUT bytes.
Quoted source text, attributed separately from HOL analysis.