CVE-2026-74683

Source
https://cve.org/CVERecord?id=CVE-2026-74683
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-74683.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-74683
Downstream
Published
2026-08-22T15:32:50Z
Modified
2026-08-26T03:49:54Z
Summary
Input: evdev - sanitize event type index when fetching event masks
Details

In the Linux kernel, the following vulnerability has been resolved:

Input: evdev - sanitize event type index when fetching event masks

The user-supplied event type index passed to EVIOCGMASK / EVIOCSMASK ioctls is used to index the static counts array in evdev_get_mask_cnt() and client evmasks array in evdev_get_mask().

While the event type is architecturally bounded by EV_CNT, speculative execution may mispredict bounds checks and perform out-of-bounds loads.

Sanitize the event type index in evdev_get_mask_cnt() branchlessly using array_index_mask_nospec(). This clamps the index to 0 for safe array access and forces the returned count to 0 speculatively when the index is out of bounds.

We do not need additional array_index_nospec() calls in evdev_get_mask() because evdev_get_mask_cnt() speculatively forces the count (and resulting xfer_size) to 0 for out-of-bounds types, preventing any speculative memory access to client evmasks array.

Database specific
{
    "cna_assigner": "Linux",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/74xxx/CVE-2026-74683.json"
}
References

Affected packages

Git / git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git

Affected ranges

Type
GIT
Repo
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Events
Introduced
06a16293f71927f756dcf37558a79c0b05a91641
Fixed
c79b08d8fa230871a3634e34a66e591ac2d084ef
Fixed
f27fa9b39f925d26e034a1f382cb45523138f4ae
Fixed
f3fc329acad9a71b3c077237cbac20670d2358c8
Fixed
5db341189bb7ff041d570dbe36ecca7e32913927
Fixed
433913b4a92214d76e9f0c03ad9128fec943d5f8
Fixed
4034ef247a9dde3f56660b01f0c3280dac6b1274
Fixed
810e1883d4815f29c30d900ad7333d03cc2515d1
Fixed
3abd29c61d2ef37c4102cf755b18be53bb9dbea6

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-74683.json"

Linux / Kernel

Package

Name
Kernel

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.4.0
Fixed
5.10.265
Type
ECOSYSTEM
Events
Introduced
5.11.0
Fixed
5.15.216
Type
ECOSYSTEM
Events
Introduced
5.16.0
Fixed
6.1.183
Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.6.152
Type
ECOSYSTEM
Events
Introduced
6.7.0
Fixed
6.12.104
Type
ECOSYSTEM
Events
Introduced
6.13.0
Fixed
6.18.45
Type
ECOSYSTEM
Events
Introduced
6.19.0
Fixed
7.1.9

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-74683.json"