« Volver al listado

CVE-2026-74683

Estado: RecibidaSin puntuar—

In the Linux kernel, the following vulnerability has been resolved:

Input: evdev - sanitize event type index when fetching event masks

The user-supplied event type index passed to EVIOCGMASK / EVIOCSMASK ioctls is used to index the static counts array in evdev_get_mask_cnt() and client evmasks array in evdev_get_mask().

While the event type is architecturally bounded by EV_CNT, speculative execution may mispredict bounds checks and perform out-of-bounds loads.

Sanitize the event type index in evdev_get_mask_cnt() branchlessly using array_index_mask_nospec(). This clamps the index to 0 for safe array access and forces the returned count to 0 speculatively when the index is out of bounds.

Leer descripción completaMostrar menos

We do not need additional array_index_nospec() calls in evdev_get_mask() because evdev_get_mask_cnt() speculatively forces the count (and resulting xfer_size) to 0 for out-of-bounds types, preventing any speculative memory access to client evmasks array.

CVSS

NVD no ha asignado puntuación CVSS a esta CVE (habitual desde el cambio de política de abril de 2026).

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-74683",
  "cveTags": [],
  "metrics": {},
  "affected": [
    {
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
      "affectedData": [
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "06a16293f71927f756dcf37558a79c0b05a91641",
              "lessThan": "c79b08d8fa230871a3634e34a66e591ac2d084ef",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "06a16293f71927f756dcf37558a79c0b05a91641",
              "lessThan": "f27fa9b39f925d26e034a1f382cb45523138f4ae",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "06a16293f71927f756dcf37558a79c0b05a91641",
              "lessThan": "f3fc329acad9a71b3c077237cbac20670d2358c8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "06a16293f71927f756dcf37558a79c0b05a91641",
              "lessThan": "5db341189bb7ff041d570dbe36ecca7e32913927",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "06a16293f71927f756dcf37558a79c0b05a91641",
              "lessThan": "433913b4a92214d76e9f0c03ad9128fec943d5f8",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "06a16293f71927f756dcf37558a79c0b05a91641",
              "lessThan": "4034ef247a9dde3f56660b01f0c3280dac6b1274",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "06a16293f71927f756dcf37558a79c0b05a91641",
              "lessThan": "810e1883d4815f29c30d900ad7333d03cc2515d1",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "06a16293f71927f756dcf37558a79c0b05a91641",
              "lessThan": "3abd29c61d2ef37c4102cf755b18be53bb9dbea6",
              "versionType": "git"
            }
          ],
          "programFiles": [
            "drivers/input/evdev.c"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "product": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "4.4"
            },
            {
              "status": "unaffected",
              "version": "0",
              "lessThan": "4.4",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "5.10.265",
              "versionType": "semver",
              "lessThanOrEqual": "5.10.*"
            },
            {
              "status": "unaffected",
              "version": "5.15.216",
              "versionType": "semver",
              "lessThanOrEqual": "5.15.*"
            },
            {
              "status": "unaffected",
              "version": "6.1.183",
              "versionType": "semver",
              "lessThanOrEqual": "6.1.*"
            },
            {
              "status": "unaffected",
              "version": "6.6.152",
              "versionType": "semver",
              "lessThanOrEqual": "6.6.*"
            },
            {
              "status": "unaffected",
              "version": "6.12.104",
              "versionType": "semver",
              "lessThanOrEqual": "6.12.*"
            },
            {
              "status": "unaffected",
              "version": "6.18.45",
              "versionType": "semver",
              "lessThanOrEqual": "6.18.*"
            },
            {
              "status": "unaffected",
              "version": "7.1.9",
              "versionType": "semver",
              "lessThanOrEqual": "7.1.*"
            },
            {
              "status": "unaffected",
              "version": "7.2",
              "versionType": "original_commit_for_fix",
              "lessThanOrEqual": "*"
            }
          ],
          "programFiles": [
            "drivers/input/evdev.c"
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2026-08-22T16:16:42.617",
  "references": [
    {
      "url": "https://git.kernel.org/stable/c/3abd29c61d2ef37c4102cf755b18be53bb9dbea6",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/4034ef247a9dde3f56660b01f0c3280dac6b1274",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/433913b4a92214d76e9f0c03ad9128fec943d5f8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/5db341189bb7ff041d570dbe36ecca7e32913927",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/810e1883d4815f29c30d900ad7333d03cc2515d1",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/c79b08d8fa230871a3634e34a66e591ac2d084ef",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f27fa9b39f925d26e034a1f382cb45523138f4ae",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    },
    {
      "url": "https://git.kernel.org/stable/c/f3fc329acad9a71b3c077237cbac20670d2358c8",
      "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
    }
  ],
  "vulnStatus": "Received",
  "descriptions": [
    {
      "lang": "en",
      "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nInput: evdev - sanitize event type index when fetching event masks\n\nThe user-supplied event type index passed to EVIOCGMASK / EVIOCSMASK\nioctls is used to index the static counts array in evdev_get_mask_cnt()\nand client evmasks array in evdev_get_mask().\n\nWhile the event type is architecturally bounded by EV_CNT, speculative\nexecution may mispredict bounds checks and perform out-of-bounds loads.\n\nSanitize the event type index in evdev_get_mask_cnt() branchlessly using\narray_index_mask_nospec(). This clamps the index to 0 for safe array\naccess and forces the returned count to 0 speculatively when the index\nis out of bounds.\n\nWe do not need additional array_index_nospec() calls in evdev_get_mask()\nbecause evdev_get_mask_cnt() speculatively forces the count (and\nresulting xfer_size) to 0 for out-of-bounds types, preventing any\nspeculative memory access to client evmasks array."
    }
  ],
  "lastModified": "2026-08-25T06:18:51.003",
  "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
}