CVE-2026-74673: Input: evdev - fix information leak in evdev_pass_values()

Published Aug 22, 2026
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

Input: evdev - fix information leak in evdevpassvalues()

In evdevpassvalues(), the inputevent structure is allocated on the kernel stack and populated field-by-field. However, it is never fully initialized. On architectures where struct inputevent contains explicit or implicit padding (such as the 32-bit pad field on SPARC64), these padding bytes are left uninitialized.

When this event structure is subsequently passed to the client buffer and later copied to userspace, the uninitialized padding bytes leak kernel stack memory, potentially exposing sensitive information.

Similar issues exist in evdevqueuesyndropped and passevent.

Fix this by explicitly zeroing the entire event structure with memset() before populating its fields. This ensures all padding bytes are cleared before the data crosses the security boundary.

Affected Software

1 affected component
Linux Linux kernel

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    In evdev_pass_values(), explicitly clear the entire allocated input_event structure using memset() before it is populated field-by-field and passed to the client buffer, so no uninitialized padding bytes leak to userspace.

    Linux kernel (Input: evdev) memset initialization of struct input_event padding/uninitialized bytes in evdev_pass_values() = memset(input_event, 0, sizeof(*input_event))
  2. Configuration

    In __evdev_queue_syn_dropped and __pass_event, explicitly zero the entire relevant event structure (including explicit/implicit padding) with memset() before copying to client/userspace, to prevent information leakage from uninitialized padding.

    Linux kernel (Input: evdev) memset initialization for event structures in __evdev_queue_syn_dropped and __pass_event = memset(..., 0, sizeof(...))

Event History

Aug 22, 2026
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
Description
Data Sourced
via NVD·04:16 PM
Description

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203