Impact
A vulnerability in the Linux kernel allows user‑supplied input to the EVIOCGMASK and EVIOCSMASK ioctl calls to be used as an index for internal arrays that are not properly sanitized. This attack permits out‑of‑bounds load operations during speculative execution, potentially leaking data from memory that the user should not be able to read. The weakness could lead to confidentiality compromise by exposing kernel or user data through side‑channel or direct read paths. The vulnerability is expressed via a missing bounds check in the function that counts event masks, creating a narrow attack surface that can be triggered by any user with access to the relevant ioctl.
Affected Systems
All Linux kernel users are affected because the vulnerability exists in the core evdev subsystem and there are no version restrictions listed. Kernel packages that expose the EVIOCGMASK/EVIOCSMASK ioctls, such as those built with standard input devices, will be impacted.
Risk and Exploitability
The exploitability requires local user access to the evdev ioctl interface. The CVSS score is 5.5, and the EPSS indicates a probability of exploitation of less than 1%, with the vulnerability not listed in the CISA KEV catalog. The lack of a bounds check in the kernel evdev subsystem suggests a medium severity if exploited; the speculative execution vector allows potential side‑channel leakage of kernel memory contents. Consequently, the risk warrants immediate attention and remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA