Logo
componentlibinput
Name
libinput
Version
1.31.3
Type
library
Description
Library to handle input devices in Wayland compositors
Licenses
MIT
PURL
-
CPE
cpe:2.3:*:freedesktop:libinput:1.31.3:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
kirkstone
1.19.4
scarthgap
1.25.0

Vulnerabilities#


Name
Analysis
Description
Not Affected
A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potentially expose sensitive data if the memory location is re-used, leading to information disclosure. For this exploit to work, Lua plugins must be enabled in libinput and loaded by the compositor.