Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4626-1 | libinput security update |
Debian DSA |
DSA-6339-1 | libinput security update |
Tue, 09 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary Root Code Execution via Udev Property Injection in libinput | libinput: local privilege escalation via crafted uinput devices |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 04 Jun 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 04 Jun 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Arbitrary Root Code Execution via Udev Property Injection in libinput |
Thu, 04 Jun 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution | |
| First Time appeared |
Freedesktop
Freedesktop libinput |
|
| Weaknesses | CWE-93 | |
| CPEs | cpe:2.3:a:freedesktop:libinput:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Freedesktop
Freedesktop libinput |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-06-04T18:12:18.647Z
Reserved: 2026-06-04T16:41:35.817Z
Link: CVE-2026-50292
Updated: 2026-06-04T18:12:14.968Z
Status : Analyzed
Published: 2026-06-04T18:16:32.530
Modified: 2026-06-05T21:06:28.800
Link: CVE-2026-50292
OpenCVE Enrichment
Updated: 2026-06-09T02:15:07Z
Debian DLA
Debian DSA