Opened 4 months ago
Closed 2 months ago
#23416 closed enhancement (fixed)
libinput-1.31.3 (Xorg driver)
| Reported by: | Bruce Dubbs | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 98-Security |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
New point version.
Change History (6)
comment:1 by , 4 months ago
| Priority: | normal → elevated |
|---|
comment:2 by , 4 months ago
========================================= libinput Security Advisory: June 4, 2026 ========================================= An issue has been found in libinput: 1) libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution libinput uses a udev helper called libinput-device-group. This helper uses a device's phys sysattr as one element of a udev property value which is printed as a KEY=VALUE pair and imported as ENV by udev. A malicious uinput or uhid device that sets a phys sysattr containing \n caused the output to be interpreted as two separate KEY=VALUE pairs by udev. This could cause arbitrary execution as root (e.g. by setting the REMOVE_CMD property). A CVE has been requested for this issue but did not get assigned in time for this disclosure. Upstream issue: https://gitlab.freedesktop.org/libinput/libinput/-/work_items/1296 Upstream fix: https://gitlab.freedesktop.org/libinput/libinput/-/commit/76f0d8a7f57e2868882864b4611281f12f704b55 Versions affected: libinput <= 1.31.2 and <= 1.30.3 Fixed versions: libinput 1.31.3, 1.30.4 Affected distributions/compositors: ----------------------------------- Affected are libinput versions 1.31.2 and 1.30.3 and all earlier versions. To exploit this vulnerability an attacker needs to create a malicious uinput or uhid device. uinput is typically restricted to root but may be tagged with uaccess by custom udev rules. On Fedora, the following packages ship such a rule: steam-devices, antimicrox and kdeconnectd. If any of these packages are *installed*, uinput devices can be created by the user logged into a seat. uhid is typically restricted to root. I am not aware of packages shipping udev rules that provide uaccess to /dev/uhid. Acknowledgements ---------------- Many thanks to Csome for reporting this issue.
This has now been assigned CVE-2026-50265.
comment:3 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | new → assigned |
comment:4 by , 4 months ago
| Owner: | changed from to |
|---|---|
| Status: | assigned → new |
Fixed at 41ffcce52a. Leaving open for SA.
comment:5 by , 3 months ago
| Milestone: | 13.1 → 98-Security |
|---|
comment:6 by , 2 months ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Advisory sa-13.0-160 has been issued.
Note:
See TracTickets
for help on using tickets.

Changelog
"libinput-device-group: sanitize phys before printing it" is a security fix. It doesn't have a CVE yet, but is in the process of being assigned. More information can be found out about it here: https://gitlab.freedesktop.org/libinput/libinput/-/work_items/1296. Marking it as elevated until we get a rating.