CVE-2026-50292
EUVD-2026-3430204.06.2026, 18:16
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| freedesktop | libinput | 𝑥 < 1.30.4 | CNA |
| freedesktop | libinput | 1.31.0 ≤ 𝑥 < 1.31.3 | CNA |
Debian Releases