On Tue, Sep 01, 2026 at 10:06:26AM -0300, Iván Ezequiel Rodriguez wrote:
Two places in the input layer copy a user supplied, possibly short
buffer into an uninitialized on-stack structure and then keep the whole
structure, including the part that was never written. In both cases the
stale stack bytes can be read back from userspace.
Patch 1: EVIOCSABS copies min(_IOC_SIZE(cmd), sizeof(struct
input_absinfo)) bytes into an uninitialized struct and stores the result
in dev->absinfo[]. EVIOCGABS returns it. Only the resolution field is
currently cleared for short sizes.
Patch 2: the compat path of input_ff_effect_from_user() aliases the
native struct ff_effect with the smaller struct ff_effect_compat and
copies only the compat sized prefix, leaving the tail untouched.
input_ff_upload() stores the full structure, which a uinput based force
feedback daemon can read back via UI_BEGIN_FF_UPLOAD.
Both are fixed by zeroing the structure before the copy. The patches are
independent of each other.
Compile tested on x86_64 with CONFIG_INPUT_EVDEV, CONFIG_INPUT_UINPUT
and CONFIG_IA32_EMULATION enabled.
Applied the lot, thank you.
--
Dmitry