Use of Uninitialized Variable in Linux kernel - CVE-2026-74673
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to an uninitialized stack-based structure in evdev event handling functions when copying input_event structures to userspace. A local user can read crafted event data from the evdev client buffer to disclose sensitive information.
The issue affects padding bytes in struct input_event on architectures where explicit or implicit padding is present.
Affected software
Debian Linux
linux (Debian package)
How to mitigate CVE-2026-74673
linux (Debian package) - update to 6.12.105-1
External References
- https://git.kernel.org/stable/c/06a286b320236508d02ab2ccc9496352748652a8
- https://git.kernel.org/stable/c/7d17e9454a9af3ec7aebb88b41a9deedd5b19a6b
- https://git.kernel.org/stable/c/7e55ca1080f09d9f7112c7f20ac31f682c1f2374
- https://git.kernel.org/stable/c/90f305f2c7a30257c683e13f4bf7c798eea992a0
- https://git.kernel.org/stable/c/bd3c4108a56de34380edab670065e86283cb3029
- https://git.kernel.org/stable/c/c6d5fa46c1ee25d068fc730fd377f0f54188d290
- https://git.kernel.org/stable/c/d2e3839419ac4047835762c4d7712bda1101b57e
- https://git.kernel.org/stable/c/e748811d9b80a3e101110ff4b3c612e5fca54d98