Logo
vulnerabilityCVE-2026-35093
Name
CVE-2026-35093
Source
NVD ( link)Debian ( link)
Description
A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run unauthorized code with the same permissions as the program using libinput, such as a graphical compositor. This could lead to the attacker monitoring keyboard input and sending that information to an external location.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libinput
Exploitable

Vulnerability Ratings#


8.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.27.0
Not Affected
buildroot
master
1.31.3
Not Affected
openwrt
master
1.31.3-r1
Not Affected
openwrt
openwrt-25.12
1.28.1-r1
Exploitable
yocto
kirkstone
1.19.4
Exploitable
yocto
scarthgap
1.25.0
Exploitable