CVE-2026-50292
EUVD-2026-3430204.06.2026, 18:16
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| freedesktop | libinput | 𝑥 < 1.30.4 |
| freedesktop | libinput | 1.31.0 ≤ 𝑥 < 1.31.3 |
𝑥
= Vulnerable software versions
Debian Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libinput-devel |
| ||||||||||||
| libinput-tools |
| ||||||||||||
| libinput-udev |
| ||||||||||||
| libinput10 |
|
Amazon Linux Releases
Amazon Package | |||||
|---|---|---|---|---|---|
| libinput |
| ||||
| libinput-debuginfo |
| ||||
| libinput-debugsource |
| ||||
| libinput-devel |
| ||||
| libinput-test |
| ||||
| libinput-test-debuginfo |
| ||||
| libinput-utils |
| ||||
| libinput-utils-debuginfo |
|