PT-2026-106530 · Linux · Linux
CVE-2026-98201
·
Publicado
2026-10-06
·
Atualizado
2026-10-06
Nenhuma
Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
In the Linux kernel, the following vulnerability has been resolved:
Input: zero ff effect before compat copy in input ff effect from user
In the compat path input ff effect from user() aliases the caller's
native struct ff effect with the smaller struct ff effect compat and
copies only the compat sized prefix:
compat effect = (struct ff effect compat *)effect;
if (copy from user(compat effect, buffer,
sizeof(struct ff effect compat)))The tail of the native structure is never written. Callers pass an
uninitialized on-stack object, for example evdev do ioctl() for
EVIOCSFF, so those bytes keep their previous stack contents.
input ff upload() then stores the full native structure in
ff->effects[id], from where a uinput based force feedback daemon can
read it back via UI BEGIN FF UPLOAD, disclosing kernel stack memory to
userspace.
Zero the effect before the compat copy.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Linux