Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-98205— Input: evdev - zero absinfo before partial copy in EVIOCSABS

Quick assessment

Affected
Linux Linux
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 Linux 内核中,以下漏洞已得到修复: 输入子系统:evdev - 在执行 EVIOCSABS 的部分拷贝前,将 absinfo 初始化为零 EVIOCSABS 处理程序会将用户提供的 ioctl 大小所限定的数据拷贝到栈上未初始化的 结构中: 该 值来源于 ioctl 命令的 ,因此完全由用户空间控制。当拷贝尺寸较小时,结构体的尾部仍将保留内核栈上的残留数据,随后整个结构体会被存入设备: 而 会将该结构体返回给用户空间,从而泄露栈上陈旧的(未初始化)数据。目前仅对 (分辨率)字段进行了清零操作,这仅适用于传

AI Predicted 7.8 Difficulty: Easy EPSS 0.18% · P7

Affected Version Matrix 18

VendorProduct Version RangeStatus
Linux Linux 448cd1664a573e69f54bfd32f3bb7220212b6cf5< c0aebb57b73c7d06ad21731099afe119b113c403 affected
448cd1664a573e69f54bfd32f3bb7220212b6cf5< 89b6ffa4bc10c436fa9aecc73be105124cd58a35 affected
448cd1664a573e69f54bfd32f3bb7220212b6cf5< e834e134a32b6a5c600fa539bb49146f617743ab affected
448cd1664a573e69f54bfd32f3bb7220212b6cf5< af5f7130cbf39e6e12336d0b7a5f6e76e4e1526b affected
448cd1664a573e69f54bfd32f3bb7220212b6cf5< 30b853a3d71f16bd0aa66b604bc37dd1254a19b3 affected
448cd1664a573e69f54bfd32f3bb7220212b6cf5< 71e5619db11dd6429101bd967230d0321ec5ea26 affected
448cd1664a573e69f54bfd32f3bb7220212b6cf5< 3dfe48d5307a1ba22c58231d04257737015569ca affected
448cd1664a573e69f54bfd32f3bb7220212b6cf5< 8b852965b8eaf910c314dc346967ed82c8d4f235 affected
… +10 more rows
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-98205

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Input: evdev - zero absinfo before partial copy in EVIOCSABS
Source: CVE Program / CVE List V5
Vulnerability Description
In the Linux kernel, the following vulnerability has been resolved: Input: evdev - zero absinfo before partial copy in EVIOCSABS The EVIOCSABS handler copies at most the user supplied ioctl size into an uninitialized on-stack struct input_absinfo: if (copy_from_user(&abs, p, min_t(size_t, size, sizeof(struct input_absinfo)))) The size comes from _IOC_SIZE() of the ioctl command and is therefore fully controlled by userspace. A short size leaves the trailing part of the structure holding whatever was on the kernel stack, and the whole structure is then stored into the device: dev->absinfo[t] = abs; EVIOCGABS hands that back to userspace, disclosing the stale stack bytes. Only the resolution field is currently cleared, which covers the legacy struct layout but not an arbitrarily short size. Zero the structure before the copy so any part not supplied by the caller reads back as zero. The existing resolution fixup is kept, since it also handles a size that partially overlaps that field.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Linux Linux 448cd1664a573e69f54bfd32f3bb7220212b6cf5 ~ c0aebb57b73c7d06ad21731099afe119b113c403 -
Linux Linux 2.6.36 -

II. Public POCs for CVE-2026-98205

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-98205

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-98205 (8)

Same Patch Batch · Linux · 2026-10-06 · 208 CVEs total

CVE-2026-98323 9.8 CRITICAL RDMA/siw: Bound fragmented header copies by the remaining length
CVE-2026-98365 9.8 CRITICAL RDMA/rxe: Fix integer overflow in mr_check_range() leading to OOB access
CVE-2026-98282 8.8 HIGH powerpc/iommu: Fix the overflow validation in iommu_tce_check_ioba
CVE-2026-98283 8.8 HIGH KVM: PPC: Book3S HV: fix use-after-free in kvmhv_emulate_tlbie_all_lpid()
CVE-2026-98339 8.8 HIGH wifi: cfg80211: don't filter by BSS type when removing stale entries
CVE-2026-98171 8.8 HIGH smb: client: fix next_buffer UAF and NextCommand bounds in compound PDUs
CVE-2026-98261 8.1 HIGH cifs: Fix server use-after-free in cifs_chan_skip_or_disable()
CVE-2026-98357 8.1 HIGH IB/isert: wait for deferred control PDU completions before releasing the connection
CVE-2026-98239 8.1 HIGH net: lan743x: fix RX checksum use-after-free
CVE-2026-98341 7.8 HIGH wifi: cfg80211: don't free driver-owned scan requests
CVE-2026-98324 7.8 HIGH dmaengine: pxa: fix double counting of the hw descriptors
CVE-2026-98228 7.8 HIGH mips: select CONFIG_WEAK_REORDERING_BEYOND_LLSC from CONFIG_EYEQ
CVE-2026-98229 7.8 HIGH xfrm: save input state data before secpath resets
CVE-2026-98320 7.8 HIGH netfilter: flowtable: hold reference on ct until flow is released
CVE-2026-98318 7.8 HIGH smb: client: validate absolute native symlink targets before NT fixups
CVE-2026-98315 7.8 HIGH ntfs: protect runlist updates with the runlist lock
CVE-2026-98260 7.8 HIGH exec: Cleanup POSIX timers right after de_thread()
CVE-2026-98256 7.8 HIGH signal: Prevent exec() race
CVE-2026-98258 7.8 HIGH posix-cpu-timers: Prevent freeing a timer which is queued on the expiry list
CVE-2026-98254 7.8 HIGH swiotlb: use the adjusted address for the highmem page lookup

Showing top 20 of 208 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-98205

No comments yet


Leave a comment