PT-2026-106530 · Linux · Linux

CVE-2026-98201

·

Published

2026-10-06

·

Updated

2026-10-06

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
Input: zero ff effect before compat copy in input ff effect from user
In the compat path input ff effect from user() aliases the caller's native struct ff effect with the smaller struct ff effect compat and copies only the compat sized prefix:
compat effect = (struct ff effect compat *)effect;

if (copy from user(compat effect, buffer,
		  sizeof(struct ff effect compat)))
The tail of the native structure is never written. Callers pass an uninitialized on-stack object, for example evdev do ioctl() for EVIOCSFF, so those bytes keep their previous stack contents. input ff upload() then stores the full native structure in ff->effects[id], from where a uinput based force feedback daemon can read it back via UI BEGIN FF UPLOAD, disclosing kernel stack memory to userspace.
Zero the effect before the compat copy.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-98201

Affected Products

Linux