Skip to main content

Vendor/product archive

freedesktop / libinput CVEs

Beta · best-effort

4 CVEs tagged to freedesktop / libinput0 Critical, 3 High, 0 Medium, 1 Low, 0 Unrated.

CVE-2026-50292

Published Jun 4, 2026

In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution

CVSS 7.4 · High
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2026-35094

Published Apr 1, 2026

A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a ga…

CVSS 3.3 · Low
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-35093

Published Apr 1, 2026

A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrict…

CVSS 8.8 · High
evidence mentions
5
Buzz score
35.9
Vendor/product tagsBeta · best-effort
Showing 1-4 of 4 CVEsPage 1 of 1