PT-2026-106530 · Linux · Linux

CVE-2026-98201

·

Publicado

2026-10-06

·

Atualizado

2026-10-06

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
Input: zero ff effect before compat copy in input ff effect from user
In the compat path input ff effect from user() aliases the caller's native struct ff effect with the smaller struct ff effect compat and copies only the compat sized prefix:
compat effect = (struct ff effect compat *)effect;

if (copy from user(compat effect, buffer,
		  sizeof(struct ff effect compat)))
The tail of the native structure is never written. Callers pass an uninitialized on-stack object, for example evdev do ioctl() for EVIOCSFF, so those bytes keep their previous stack contents. input ff upload() then stores the full native structure in ff->effects[id], from where a uinput based force feedback daemon can read it back via UI BEGIN FF UPLOAD, disclosing kernel stack memory to userspace.
Zero the effect before the compat copy.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2026-98201

Produtos afetados

Linux