Logo
vulnerabilityCVE-2026-50292
Name
CVE-2026-50292
Source
NVD ( link)Debian ( link)
Description
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libinput
Exploitable

Vulnerability Ratings#


7.4
CVSSv31
9.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.27.0
Patched
buildroot
master
1.31.3
Not Affected
openwrt
master
1.31.3-r1
Not Affected
openwrt
openwrt-25.12
1.28.1-r1
Exploitable
yocto
master
1.30.2
Patched
yocto
scarthgap
1.25.0
Exploitable

Resolved with patches#


libinput (buildroot:2025.02.x)

#
Title
Author
Resolve
1
util: don't call function in macro argument
=?UTF-8?q?Kacper=20Piwi=C5=84ski?= <vfjpl1@gmail.com>
CVE-2026-50292
2
util: sanitize control characters in str_sanitize()
Peter Hutterer <peter.hutterer@who-t.net>
CVE-2026-50292
3
libinput-device-group: sanitize phys before printing it
Peter Hutterer <peter.hutterer@who-t.net>
CVE-2026-50292

libinput (yocto:master)

#
Title
Author
Resolve
1
libinput-device-group: sanitize phys before printing it
Peter Hutterer <peter.hutterer@who-t.net>
CVE-2026-50292