Description

Context

UEnhancedPlayerInput::EvaluateInputComponentDelegates iterates the delegates that triggered this tick. For each one it resolves the action's state via FindActionInstanceData(DelegateAction): a raw pointer into the ActionInstanceData TMap. It then calls Delegate->Execute(*ActionData), which runs arbitrary user code, and continues to use ActionData after that call returns.

Problem

If the invoked user code adds or removes an input mapping context with FModifyContextOptions::bForceImmediately = true, RebuildControlMappings() runs synchronously, inside the delegate. It completes by calling InitializeMappingActionModifiers → FindOrAddActionEventData → ActionInstanceData.Emplace for each action in the incoming context. Growing the TMap reallocates its backing TSparseArray and relocates every element, so ActionData becomes a wild pointer even though the entry logically still exists.

On return from Execute there are two dereferences of that pointer:

  • ActionData->TriggerEvent = OriginalEvent;
  • GetPathNameSafe(ActionData->GetSourceAction()), ActionData->GetValue()

If ActionData got moved, these accesses are invalid and corrupt memory on write or access garbage on read.

Steps to Reproduce

Attached a repro project:

  • Edit the included .bat file to point to local editor (5.8+)
  • Use it to open editor with -stomp2malloc
  • Start PIE in any map.
    • Default PlayerController will have key bindings set up
  • Hold K to trigger the crash

New project repro:

  1. Blank C++ project with Enhanced Input as the default player input / input component classes.
  2. Create IA_Repro (digital) with a Hold trigger, threshold 0.2s. Create IMC_Repro mapping it to K. Create IMC_NextMode mapping ~6 otherwise-unused input actions to distinct keys.
  3. In a PlayerController, bind IA_Repro on ETriggerEvent::Triggered. In the handler:
    FModifyContextOptions Options;
    Options.bForceImmediately = true;
    Subsystem->RemoveMappingContext(ReproContext, Options);
    Subsystem->AddMappingContext(NextContext, 0, Options);
  4. Launch the editor with -stomp2malloc -MallocStomp2MinSize=64 -MallocStomp2MaxSize=4096 to catch memory stomps instead of silently corrupting
  5. PIE, hold K.
Callstack
UnrealEditor_EnhancedInput!UEnhancedPlayerInput::EvaluateInputComponentDelegates() [EnhancedPlayerInput.cpp:889]
UnrealEditor_Engine!UPlayerInput::EvaluateInputDelegates() [PlayerInput.cpp:1509]
UnrealEditor_EnhancedInput!UEnhancedPlayerInput::EvaluateInputDelegates() [EnhancedPlayerInput.cpp:430]
UnrealEditor_Engine!UPlayerInput::ProcessInputStack() [PlayerInput.cpp:1308]
UnrealEditor_Engine!APlayerController::ProcessPlayerInput() [PlayerController.cpp:2762]
UnrealEditor_Engine!APlayerController::TickPlayerInput() [PlayerController.cpp:5495]
UnrealEditor_Engine!APlayerController::PlayerTick() [PlayerController.cpp:2328]
UnrealEditor_Engine!APlayerController::TickActor() [PlayerController.cpp:5647]
UnrealEditor_Engine!FActorTickFunction::ExecuteTick() [Actor.cpp:379]
UnrealEditor_Engine!TGraphTask<FTickFunctionTask>::ExecuteTask() [TaskGraphInterfaces.h:703]
UnrealEditor_Core!UE::Tasks::Private::FTaskBase::TryExecuteTask() [TaskPrivate.h:524]
UnrealEditor_Core!FNamedTaskThread::ProcessTasksNamedThread() [TaskGraph.cpp:807]
UnrealEditor_Core!FNamedTaskThread::ProcessTasksUntilIdle() [TaskGraph.cpp:707]
UnrealEditor_Core!FTaskGraphCompatibilityImplementation::ProcessUntilTasksComplete() [TaskGraph.cpp:1620]
UnrealEditor_Engine!FTickTaskSequencer::ReleaseTickGroup() [TickTaskManager.cpp:1040]
UnrealEditor_Engine!FTickTaskManager::RunTickGroup() [TickTaskManager.cpp:2134]
UnrealEditor_Engine!UWorld::Tick() [LevelTick.cpp:1750]
UnrealEditor_UnrealEd!UEditorEngine::Tick() [EditorEngine.cpp:2171]
UnrealEditor_UnrealEd!UUnrealEdEngine::Tick() [UnrealEdEngine.cpp:546]
UnrealEditor!FEngineLoop::Tick() [LaunchEngineLoop.cpp:5859]
UnrealEditor!GuardedMain() [Launch.cpp:190]
UnrealEditor!GuardedMainWrapper() [LaunchWindows.cpp:123]
UnrealEditor!LaunchWindowsStartup() [LaunchWindows.cpp:277]
UnrealEditor!WinMain() [LaunchWindows.cpp:338]

Have Comments or More Details?

There's no existing public thread on this issue, so head over to Questions & Answers just mention UE-398245 in the post.

0
Login to Vote

Unresolved
ComponentUE - Gameplay - Input
Affects Versions5.7, 5.8
Target Fix6.0
CreatedSep 21, 2026
UpdatedSep 25, 2026
View Jira Issue