{"id":"AZL-106182","summary":"CVE-2026-98201 affecting package kernel 6.6.157.1-1","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nInput: zero ff_effect before compat copy in input_ff_effect_from_user\n\nIn the compat path input_ff_effect_from_user() aliases the caller's\nnative struct ff_effect with the smaller struct ff_effect_compat and\ncopies only the compat sized prefix:\n\n\tcompat_effect = (struct ff_effect_compat *)effect;\n\n\tif (copy_from_user(compat_effect, buffer,\n\t\t\t   sizeof(struct ff_effect_compat)))\n\nThe tail of the native structure is never written. Callers pass an\nuninitialized on-stack object, for example evdev_do_ioctl() for\nEVIOCSFF, so those bytes keep their previous stack contents.\ninput_ff_upload() then stores the full native structure in\nff-\u003eeffects[id], from where a uinput based force feedback daemon can\nread it back via UI_BEGIN_FF_UPLOAD, disclosing kernel stack memory to\nuserspace.\n\nZero the effect before the compat copy.","modified":"2026-10-07T14:16:59.016604484Z","published":"2026-10-06T09:18:05Z","upstream":["CVE-2026-98201"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98201"}],"affected":[{"package":{"name":"kernel","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/kernel"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"6.6.157.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106182.json"}}],"schema_version":"1.9.0"}