Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-74673

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
22/08/2026
Última modificación:
22/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> Input: evdev - fix information leak in evdev_pass_values()<br /> <br /> In evdev_pass_values(), the input_event structure is allocated on the<br /> kernel stack and populated field-by-field. However, it is never fully<br /> initialized. On architectures where struct input_event contains explicit<br /> or implicit padding (such as the 32-bit __pad field on SPARC64), these<br /> padding bytes are left uninitialized.<br /> <br /> When this event structure is subsequently passed to the client buffer<br /> and later copied to userspace, the uninitialized padding bytes leak<br /> kernel stack memory, potentially exposing sensitive information.<br /> <br /> Similar issues exist in __evdev_queue_syn_dropped and __pass_event.<br /> <br /> Fix this by explicitly zeroing the entire event structure with memset()<br /> before populating its fields. This ensures all padding bytes are cleared<br /> before the data crosses the security boundary.

Impacto