A vulnerability was found in Linux Kernel up to 7.2-rc2. It has been declared as critical. The affected element is the function mt_release_contacts/mt_process_slot/mt_release_pending_palms of the component HID: multitouch. Executing a manipulation of the argument maxcontacts/num_slots/mt_io_flags can lead to out-of-bounds read.

This vulnerability appears as CVE-2026-64364. The attack may be performed from remote. There is no available exploit.

It is recommended to upgrade the affected component.