Opened 4 months ago

Closed 2 months ago

#23416 closed enhancement (fixed)

libinput-1.31.3 (Xorg driver)

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: elevated Milestone: 98-Security
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (6)

comment:1 by zeckma, 4 months ago

Priority: normal → elevated

Changelog

  • tablet: allow for the eraser button to be any button
  • tools/record: replace the timestamp with usec_t
  • tools/record: default to libinput-recording.yml with --autorestart
  • tools/record: fix broken autorestart for timeouts >=5s
  • totem: require both touch size axes to have resolution
  • evdev: be stricter about devices with odd absinfo values
  • pad: ignore invalid strip axis values
  • util: sanitize control characters in str_sanitize()
  • tools: sanitize device names in libinput-record YAML output
  • libinput-device-group: sanitize phys before printing it
  • libinput 1.31.3

"libinput-device-group: sanitize phys before printing it" is a security fix. It doesn't have a CVE yet, but is in the process of being assigned. More information can be found out about it here: ​https://gitlab.freedesktop.org/libinput/libinput/-/work_items/1296. Marking it as elevated until we get a rating.

comment:2 by Joe Locash, 4 months ago

=========================================
libinput Security Advisory: June 4, 2026
=========================================

An issue has been found in libinput:

1) libinput-device-group unescaped phys output can inject udev properties
   leading to arbitrary root code execution

libinput uses a udev helper called libinput-device-group. This helper uses a
device's phys sysattr as one element of a udev property value which is printed
as a KEY=VALUE pair and imported as ENV by udev.

A malicious uinput or uhid device that sets a phys sysattr containing \n caused
the output to be interpreted as two separate KEY=VALUE pairs by udev. This could
cause arbitrary execution as root (e.g. by setting the REMOVE_CMD property).

A CVE has been requested for this issue but did not get assigned in time for
this disclosure.

Upstream issue: https://gitlab.freedesktop.org/libinput/libinput/-/work_items/1296
Upstream fix: https://gitlab.freedesktop.org/libinput/libinput/-/commit/76f0d8a7f57e2868882864b4611281f12f704b55
Versions affected: libinput <= 1.31.2 and <= 1.30.3
Fixed versions: libinput 1.31.3, 1.30.4

Affected distributions/compositors:
-----------------------------------

Affected are libinput versions 1.31.2 and 1.30.3 and all earlier versions.

To exploit this vulnerability an attacker needs to create a malicious uinput or
uhid device. 

uinput is typically restricted to root but may be tagged with uaccess by custom
udev rules. On Fedora, the following packages ship such a rule: steam-devices,
antimicrox and kdeconnectd. If any of these packages are *installed*, uinput
devices can be created by the user logged into a seat.

uhid is typically restricted to root. I am not aware of packages shipping
udev rules that provide uaccess to /dev/uhid.

Acknowledgements
----------------

Many thanks to Csome for reporting this issue.

This has now been assigned CVE-2026-50265.

comment:3 by Joe Locash, 4 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:4 by Joe Locash, 4 months ago

Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new

Fixed at 41ffcce52a. Leaving open for SA.

comment:5 by Bruce Dubbs, 3 months ago

Milestone: 13.1 → 98-Security

comment:6 by Bruce Dubbs, 2 months ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.0-160 has been issued.

Note: See TracTickets for help on using tickets.