CVE-2026-98205
Received Received - Intake

Information Leak in Linux Kernel evdev Subsystem

Vulnerability report for CVE-2026-98205, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: kernel.org

Description

In the Linux kernel, the following vulnerability has been resolved: Input: evdev - zero absinfo before partial copy in EVIOCSABS The EVIOCSABS handler copies at most the user supplied ioctl size into an uninitialized on-stack struct input_absinfo: if (copy_from_user(&abs, p, min_t(size_t, size, sizeof(struct input_absinfo)))) The size comes from _IOC_SIZE() of the ioctl command and is therefore fully controlled by userspace. A short size leaves the trailing part of the structure holding whatever was on the kernel stack, and the whole structure is then stored into the device: dev->absinfo[t] = abs; EVIOCGABS hands that back to userspace, disclosing the stale stack bytes. Only the resolution field is currently cleared, which covers the legacy struct layout but not an arbitrarily short size. Zero the structure before the copy so any part not supplied by the caller reads back as zero. The existing resolution fixup is kept, since it also handles a size that partially overlaps that field.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 9 associated CPEs
Vendor Product Version / Range
Linux Linux 448cd1664a573e69f54bfd32f3bb7220212b6cf5
Linux Linux 448cd1664a573e69f54bfd32f3bb7220212b6cf5
Linux Linux 448cd1664a573e69f54bfd32f3bb7220212b6cf5
Linux Linux 448cd1664a573e69f54bfd32f3bb7220212b6cf5
Linux Linux 448cd1664a573e69f54bfd32f3bb7220212b6cf5
Linux Linux 448cd1664a573e69f54bfd32f3bb7220212b6cf5
Linux Linux 448cd1664a573e69f54bfd32f3bb7220212b6cf5
Linux Linux 448cd1664a573e69f54bfd32f3bb7220212b6cf5
Linux Linux 2.6.36

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Linux kernel involves improper handling of the EVIOCSABS ioctl command. When userspace provides a short size for copying input_absinfo data, uninitialized kernel stack memory may be exposed. The fix ensures the entire struct is zeroed before copying user data to prevent stale stack bytes from being disclosed.

Detection Guidance

This vulnerability is specific to the Linux kernel's evdev subsystem and requires local access to detect. Check kernel version with 'uname -a' and look for affected versions. Monitor kernel logs for unusual input device events or stack data disclosures.

Impact Analysis

An attacker with local access could exploit this to read sensitive kernel memory, potentially exposing passwords, encryption keys, or other confidential data. This could lead to privilege escalation or information disclosure on affected systems.

Mitigation Strategies

Apply the latest Linux kernel security patches immediately. If patches are unavailable, restrict access to input devices via permissions or disable untrusted user access. Monitor vendor advisories for updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-98205. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart