Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-74683

Gravedad:
Pendiente de análisis
Tipo:
No Disponible / Otro tipo
Fecha de publicación:
22/08/2026
Última modificación:
22/08/2026

Descripción

*** Pendiente de traducción *** In the Linux kernel, the following vulnerability has been resolved:<br /> <br /> Input: evdev - sanitize event type index when fetching event masks<br /> <br /> The user-supplied event type index passed to EVIOCGMASK / EVIOCSMASK<br /> ioctls is used to index the static counts array in evdev_get_mask_cnt()<br /> and client evmasks array in evdev_get_mask().<br /> <br /> While the event type is architecturally bounded by EV_CNT, speculative<br /> execution may mispredict bounds checks and perform out-of-bounds loads.<br /> <br /> Sanitize the event type index in evdev_get_mask_cnt() branchlessly using<br /> array_index_mask_nospec(). This clamps the index to 0 for safe array<br /> access and forces the returned count to 0 speculatively when the index<br /> is out of bounds.<br /> <br /> We do not need additional array_index_nospec() calls in evdev_get_mask()<br /> because evdev_get_mask_cnt() speculatively forces the count (and<br /> resulting xfer_size) to 0 for out-of-bounds types, preventing any<br /> speculative memory access to client evmasks array.

Impacto