Arbitrary Code Execution in Libinput Affects Multiple Versions
CVE-2026-50292
7.4HIGH
What is CVE-2026-50292?
In specific versions of Libinput, an issue exists where unescaped physical output from libinput-device-group can lead to the injection of udev properties. This vulnerability poses a significant risk of arbitrary code execution with root privileges, which could be exploited by an attacker to gain unauthorized access to system resources and perform malicious activities.
Affected Version(s)
libinput 0 < 1.30.4
libinput 1.31.0 < 1.31.3
