CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution |
2Fedoraproject Freedesktop2Fedora LibinputJun 17, 2026 Apr 1, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is call...Show more |
2Fedoraproject Freedesktop2Fedora LibinputJul 15, 2026 Apr 1, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run una...Show more |
A format string vulnerability was found in libinput |