CyberRota Analysis
AI-GeneratedThe vulnerability affects the Linux kernel's evdev subsystem, specifically in how it handles user-supplied event type indices during the EVIOCGMASK and EVIOCSMASK ioctl operations. An attacker could exploit this flaw through speculative execution to perform out-of-bounds memory accesses, potentially leading to information disclosure or other unintended behaviors. Organizations utilizing Linux systems, particularly those relying on input device management, should prioritize addressing this vulnerability to mitigate potential risks.
Original NVD Description
In the Linux kernel, the following vulnerability has been resolved: Input: evdev - sanitize event type index when fetching event masks The user-supplied event type index passed to EVIOCGMASK / EVIOCSMASK ioctls is used to index the static counts array in evdev_get_mask_cnt() and client evmasks array in evdev_get_mask(). While the event type is architecturally bounded by EV_CNT, speculative execution may mispredict bounds checks and perform out-of-bounds loads. Sanitize the event type index in evdev_get_mask_cnt() branchlessly using array_index_mask_nospec(). This clamps the index to 0 for safe array access and forces the returned count to 0 speculatively when the index is out of bounds. We do not need additional array_index_nospec() calls in evdev_get_mask() because evdev_get_mask_cnt() speculatively forces the count (and resulting xfer_size) to 0 for out-of-bounds types, preventing any speculative memory access to client evmasks array.