Logo
componentlibinput
Name
libinput
Version
1.27.0
Type
library
Description
-
Licenses
MIT
PURL
-
CPE
cpe:2.3:a:freedesktop:libinput:1.27.0:-:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
1.31.3

Patches#


#
Title
Author
Resolve
1
util: don't call function in macro argument
=?UTF-8?q?Kacper=20Piwi=C5=84ski?= <vfjpl1@gmail.com>
CVE-2026-50292
2
util: sanitize control characters in str_sanitize()
Peter Hutterer <peter.hutterer@who-t.net>
CVE-2026-50292
3
libinput-device-group: sanitize phys before printing it
Peter Hutterer <peter.hutterer@who-t.net>
CVE-2026-50292

Vulnerabilities#


Name
Analysis
Description
Patched
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution