CVE-2026-35094 Details
Description
A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potentially expose sensitive data if the memory location is re-used, leading to information disclosure. For this exploit to work, Lua plugins must be enabled in libinput and loaded by the compositor.
A dangling pointer vulnerability has been identified in libinput, which can be exploited by an attacker who can deploy a Lua plugin file in certain system directories. This vulnerability arises when a garbage collection cleanup function is invoked, leaving behind a pointer that can be logged to system logs. If the memory location referenced by the pointer is reused, it could lead to unauthorized exposure of sensitive data. For this vulnerability to be exploited, Lua plugins must be enabled in libinput and loaded by the compositor.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-35094 | [email protected] | Third Party AdvisoryVDB Entry |
| https://bugzilla.redhat.com/show_bug.cgi?id=2453840 | [email protected] | Issue TrackingThird Party Advisory |
| https://gitlab.freedesktop.org/libinput/libinput/-/work_items/1272 | [email protected] | Broken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-825 | Expired Pointer Dereference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| freedesktop libinput | All versions |
CPE
Remediation
| |
| fedoraproject fedora | 43 44 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 7, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | New CVE Received | [email protected] |