7.4
/ 10
HIGH
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Description
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
Basic Information
ID
CVE-2026-50292
Source
mitre
Published
Jun 4, 2026 at 16:41
Modified
Jun 4, 2026 at 18:12
Affected Product
Vendor
freedesktop
Product
libinput
Affected Versions
freedesktop libinput 0
freedesktop libinput 1.31.0
freedesktop libinput 1.31.0