PT-2026-106530 · Linux · Linux
CVE-2026-98201
·
Published
2026-10-06
·
Updated
2026-10-06
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
In the Linux kernel, the following vulnerability has been resolved:
Input: zero ff effect before compat copy in input ff effect from user
In the compat path input ff effect from user() aliases the caller's
native struct ff effect with the smaller struct ff effect compat and
copies only the compat sized prefix:
compat effect = (struct ff effect compat *)effect;
if (copy from user(compat effect, buffer,
sizeof(struct ff effect compat)))The tail of the native structure is never written. Callers pass an
uninitialized on-stack object, for example evdev do ioctl() for
EVIOCSFF, so those bytes keep their previous stack contents.
input ff upload() then stores the full native structure in
ff->effects[id], from where a uinput based force feedback daemon can
read it back via UI BEGIN FF UPLOAD, disclosing kernel stack memory to
userspace.
Zero the effect before the compat copy.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux