CVE-2026-98201
Received
Received - Intake
Input ff_effect Memory Disclosure in Linux Kernel
Vulnerability report for CVE-2026-98201, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-06
Last updated on: 2026-10-06
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
Input: zero ff_effect before compat copy in input_ff_effect_from_user
In the compat path input_ff_effect_from_user() aliases the caller's
native struct ff_effect with the smaller struct ff_effect_compat and
copies only the compat sized prefix:
compat_effect = (struct ff_effect_compat *)effect;
if (copy_from_user(compat_effect, buffer,
sizeof(struct ff_effect_compat)))
The tail of the native structure is never written. Callers pass an
uninitialized on-stack object, for example evdev_do_ioctl() for
EVIOCSFF, so those bytes keep their previous stack contents.
input_ff_upload() then stores the full native structure in
ff->effects[id], from where a uinput based force feedback daemon can
read it back via UI_BEGIN_FF_UPLOAD, disclosing kernel stack memory to
userspace.
Zero the effect before the compat copy.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 2d56f3a32c0e62f99c043d2579840f9731fe5855 |
| Linux | Linux | 2d56f3a32c0e62f99c043d2579840f9731fe5855 |
| Linux | Linux | 2d56f3a32c0e62f99c043d2579840f9731fe5855 |
| Linux | Linux | 2d56f3a32c0e62f99c043d2579840f9731fe5855 |
| Linux | Linux | 2d56f3a32c0e62f99c043d2579840f9731fe5855 |
| Linux | Linux | 2d56f3a32c0e62f99c043d2579840f9731fe5855 |
| Linux | Linux | 2d56f3a32c0e62f99c043d2579840f9731fe5855 |
| Linux | Linux | 2d56f3a32c0e62f99c043d2579840f9731fe5855 |
| Linux | Linux | 2.6.29 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |