CVE-2026-50292
Published Jun 4, 2026In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
- evidence mentions
- 6
- Buzz score
- 32.5
Vendor/product archive
4 CVEs tagged to freedesktop / libinput — 0 Critical, 3 High, 0 Medium, 1 Low, 0 Unrated.
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a ga…
A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrict…
A format string vulnerability was found in libinput