Re: [PATCH] Input: evdev - sanitize event type index when fetching event masks

Greg KH <[email protected]>
Newsgroups gmane.linux.kernel.input,gmane.linux.kernel
Message-ID <2026080412-camping-fringe-8219@gregkh>
On Mon, Aug 03, 2026 at 06:41:49PM -0700, Dmitry Torokhov wrote:
> The user-supplied event type index passed to EVIOCGMASK / EVIOCSMASK
> ioctls is used to index the static counts array in evdev_get_mask_cnt()
> and client evmasks array in evdev_get_mask().
> 
> While the event type is architecturally bounded by EV_CNT, speculative
> execution may mispredict bounds checks and perform out-of-bounds loads.
> 
> Sanitize the event type index in evdev_get_mask_cnt() branchlessly using
> array_index_mask_nospec(). This clamps the index to 0 for safe array
> access and forces the returned count to 0 speculatively when the index
> is out of bounds.
> 
> We do not need additional array_index_nospec() calls in evdev_get_mask()
> because evdev_get_mask_cnt() speculatively forces the count (and
> resulting xfer_size) to 0 for out-of-bounds types, preventing any
> speculative memory access to client evmasks array.
> 
> Reported-by: "Wagenaar, C.C.J. (Chris)" <[email protected]>
> Cc: [email protected]
> Assisted-by: Antigravity:gemini-3.6-flash
> Signed-off-by: Dmitry Torokhov <[email protected]>
> ---
>  drivers/input/evdev.c | 5 ++++-
>  1 file changed, 4 insertions(+), 1 deletion(-)
> 
> diff --git a/drivers/input/evdev.c b/drivers/input/evdev.c
> index 5764c98b4f1f..796ac7ac2b8c 100644
> --- a/drivers/input/evdev.c
> +++ b/drivers/input/evdev.c
> @@ -21,6 +21,7 @@
>  #include <linux/init.h>
>  #include <linux/input/mt.h>
>  #include <linux/major.h>
> +#include <linux/nospec.h>
>  #include <linux/device.h>
>  #include <linux/cdev.h>
>  #include "input-compat.h"
> @@ -67,8 +68,10 @@ static size_t evdev_get_mask_cnt(unsigned int type)
>  		[EV_SND]	= SND_CNT,
>  		[EV_FF]		= FF_CNT,
>  	};
> +	unsigned long mask = array_index_mask_nospec(type, EV_CNT);
>  
> -	return (type < EV_CNT) ? counts[type] : 0;
> +	/* Returns 0 for out-of-bounds types, including speculatively */
> +	return counts[type & mask] & mask;
>  }
>  
>  /* requires the buffer lock to be held */
> -- 
> 2.55.0.629.g250fe7f194-goog
> 
> 
> -- 
> Dmitry

Acked-by: Greg Kroah-Hartman <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.