Back

Input: zero ff_effect before compat copy in input_ff_effect_from_user

Published Oct 6, 2026

Description

In the compat path input_ff_effect_from_user() aliases the caller's native struct ff_effect with the smaller struct ff_effect_compat and copies only the compat sized prefix:

compat_effect = (struct ff_effect_compat *)effect;

if (copy_from_user(compat_effect, buffer, sizeof(struct ff_effect_compat)))

The tail of the native structure is never written. Callers pass an uninitialized on-stack object, for example evdev_do_ioctl() for EVIOCSFF, so those bytes keep their previous stack contents. input_ff_upload() then stores the full native structure in ff->effects[id], from where a uinput based force feedback daemon can read it back via UI_BEGIN_FF_UPLOAD, disclosing kernel stack memory to userspace.

Zero the effect before the compat copy.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (0)

No CWE recorded.

References (9)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Linux
Published Oct 6, 2026
Updated Oct 6, 2026
Reserved Sep 25, 2026

CISA Vulnrichment

No data

NVD

Status Received
Modified Oct 6, 2026

Red Hat

No data

ENISA EUVD

Assigner Linux
Published Oct 6, 2026
Updated Oct 6, 2026

GitHub

No data