CVE-2026-35094

EUVD-2026-17909
A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potentially expose sensitive data if the memory location is re-used, leading to information disclosure. For this exploit to work, Lua plugins must be enabled in libinput and loaded by the compositor.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
3.3 LOW
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 4.36%
Affected Products (NVD)
VendorProductVersion
freedesktoplibinput
-
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libinput
bookworm
1.22.1-1+deb12u1
fixed
bookworm (security)
1.22.1-1+deb12u1
fixed
bullseye
1.16.4-3
fixed
bullseye (security)
1.16.4-3+deb11u1
fixed
forky
1.31.3-1
fixed
sid
1.31.3-1
fixed
trixie
1.28.1-1+deb13u1
fixed
trixie (security)
1.28.1-1+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libinput
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
questing
not-affected
resolute
not-affected
xenial
not-affected