๐Ÿ” CVE Alert

CVE-2026-98205

UNKNOWN 0.0

Input: evdev - zero absinfo before partial copy in EVIOCSABS

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

In the Linux kernel, the following vulnerability has been resolved: Input: evdev - zero absinfo before partial copy in EVIOCSABS The EVIOCSABS handler copies at most the user supplied ioctl size into an uninitialized on-stack struct input_absinfo: if (copy_from_user(&abs, p, min_t(size_t, size, sizeof(struct input_absinfo)))) The size comes from _IOC_SIZE() of the ioctl command and is therefore fully controlled by userspace. A short size leaves the trailing part of the structure holding whatever was on the kernel stack, and the whole structure is then stored into the device: dev->absinfo[t] = abs; EVIOCGABS hands that back to userspace, disclosing the stale stack bytes. Only the resolution field is currently cleared, which covers the legacy struct layout but not an arbitrarily short size. Zero the structure before the copy so any part not supplied by the caller reads back as zero. The existing resolution fixup is kept, since it also handles a size that partially overlaps that field.

Vendor linux
Product linux
Ecosystems
Industries
Technology
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for linux linux

Be the first to know when new unknown vulnerabilities affecting linux linux are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Linux / Linux
448cd1664a573e69f54bfd32f3bb7220212b6cf5 < c0aebb57b73c7d06ad21731099afe119b113c403 448cd1664a573e69f54bfd32f3bb7220212b6cf5 < 89b6ffa4bc10c436fa9aecc73be105124cd58a35 448cd1664a573e69f54bfd32f3bb7220212b6cf5 < e834e134a32b6a5c600fa539bb49146f617743ab 448cd1664a573e69f54bfd32f3bb7220212b6cf5 < af5f7130cbf39e6e12336d0b7a5f6e76e4e1526b 448cd1664a573e69f54bfd32f3bb7220212b6cf5 < 30b853a3d71f16bd0aa66b604bc37dd1254a19b3 448cd1664a573e69f54bfd32f3bb7220212b6cf5 < 71e5619db11dd6429101bd967230d0321ec5ea26 448cd1664a573e69f54bfd32f3bb7220212b6cf5 < 3dfe48d5307a1ba22c58231d04257737015569ca 448cd1664a573e69f54bfd32f3bb7220212b6cf5 < 8b852965b8eaf910c314dc346967ed82c8d4f235
Linux / Linux
2.6.36

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
git.kernel.org: https://git.kernel.org/stable/c/c0aebb57b73c7d06ad21731099afe119b113c403 git.kernel.org: https://git.kernel.org/stable/c/89b6ffa4bc10c436fa9aecc73be105124cd58a35 git.kernel.org: https://git.kernel.org/stable/c/e834e134a32b6a5c600fa539bb49146f617743ab git.kernel.org: https://git.kernel.org/stable/c/af5f7130cbf39e6e12336d0b7a5f6e76e4e1526b git.kernel.org: https://git.kernel.org/stable/c/30b853a3d71f16bd0aa66b604bc37dd1254a19b3 git.kernel.org: https://git.kernel.org/stable/c/71e5619db11dd6429101bd967230d0321ec5ea26 git.kernel.org: https://git.kernel.org/stable/c/3dfe48d5307a1ba22c58231d04257737015569ca git.kernel.org: https://git.kernel.org/stable/c/8b852965b8eaf910c314dc346967ed82c8d4f235