CVE-2026-98201 PUBLISHED

Input: zero ff_effect before compat copy in input_ff_effect_from_user

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

Input: zero ff_effect before compat copy in input_ff_effect_from_user

In the compat path input_ff_effect_from_user() aliases the caller's native struct ff_effect with the smaller struct ff_effect_compat and copies only the compat sized prefix:

<pre>compat_effect = (struct ff_effect_compat *)effect; if (copy_from_user(compat_effect, buffer, sizeof(struct ff_effect_compat))) </pre>

The tail of the native structure is never written. Callers pass an uninitialized on-stack object, for example evdev_do_ioctl() for EVIOCSFF, so those bytes keep their previous stack contents. input_ff_upload() then stores the full native structure in ff->effects[id], from where a uinput based force feedback daemon can read it back via UI_BEGIN_FF_UPLOAD, disclosing kernel stack memory to userspace.

Zero the effect before the compat copy.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 2d56f3a32c0e62f99c043d2579840f9731fe5855 to ed0905fda39682d3da7937184397d3276abbffa8 (excl.)
  • affected from 2d56f3a32c0e62f99c043d2579840f9731fe5855 to ec174c2ab1abb76b20fa167c6db848c3d97aa838 (excl.)
  • affected from 2d56f3a32c0e62f99c043d2579840f9731fe5855 to 6c26681c5668c973bd0e951407d670ac60d9cd66 (excl.)
  • affected from 2d56f3a32c0e62f99c043d2579840f9731fe5855 to c5e573bb095d502be7cbbaa99c26a20984111c6d (excl.)
  • affected from 2d56f3a32c0e62f99c043d2579840f9731fe5855 to b878720e8bcaa4cf7163a5081f904dd6baf11b2c (excl.)
  • affected from 2d56f3a32c0e62f99c043d2579840f9731fe5855 to 0d05b43b55d4784a42ce8fb318175f8ad7d9af5a (excl.)
  • affected from 2d56f3a32c0e62f99c043d2579840f9731fe5855 to ed0406e490f48ed180df140fe2a81be26bccb1a9 (excl.)
  • affected from 2d56f3a32c0e62f99c043d2579840f9731fe5855 to f84819ef8d66931ee3998fee3c4f03230f4cb6cc (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 2.6.29 is affected
  • unaffected from 0 to 2.6.29 (excl.)
  • unaffected from 5.10.271 to 5.10.* (incl.)
  • unaffected from 5.15.222 to 5.15.* (incl.)
  • unaffected from 6.1.189 to 6.1.* (incl.)
  • unaffected from 6.6.158 to 6.6.* (incl.)
  • unaffected from 6.12.112 to 6.12.* (incl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References