CVE-2026-98201: Input: zero ff_effect before compat copy in input_ff_effect_from_user
In the Linux kernel, the following vulnerability has been resolved:
Input: zero ffeffect before compat copy in inputffeffectfromuser
In the compat path inputffeffectfromuser() aliases the caller's native struct ffeffect with the smaller struct ffeffectcompat and copies only the compat sized prefix:
compateffect = (struct ffeffectcompat )effect;
if (copyfromuser(compateffect, buffer, sizeof(struct ffeffectcompat)))
The tail of the native structure is never written. Callers pass an uninitialized on-stack object, for example evdevdoioctl() for EVIOCSFF, so those bytes keep their previous stack contents. inputffupload() then stores the full native structure in ff->effects[id], from where a uinput based force feedback daemon can read it back via UIBEGINFFUPLOAD, disclosing kernel stack memory to userspace.
Zero the effect before the compat copy.