Logo
vulnerabilityCVE-2026-35094
Name
CVE-2026-35094
Source
NVD ( link)Debian ( link)
Description
A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potentially expose sensitive data if the memory location is re-used, leading to information disclosure. For this exploit to work, Lua plugins must be enabled in libinput and loaded by the compositor.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
libinput
Not Affected

Vulnerability Ratings#


3.3
CVSSv31
5.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.27.0
Not Affected
buildroot
master
1.31.3
Not Affected
openwrt
master
1.31.3-r1
Not Affected
openwrt
openwrt-25.12
1.28.1-r1
Not Affected
yocto
kirkstone
1.19.4
Not Affected
yocto
scarthgap
1.25.0
Not Affected