CVE-2026-50265 Details
Description
Rejected reason: This CVE ID was assigned as a duplicate of CVE-2026-50292
A vulnerability in libinput allows local attackers with access to /dev/uinput to inject arbitrary udev properties through the libinput-device-group helper. This injection can lead to root code execution by exploiting REMOVE_CMD properties, which are executed when a device is removed. The vulnerability arises because the libinput-device-group output is not properly sanitized, allowing control characters to be interpreted as separate udev property records. The issue is present in libinput versions prior to the latest fix.
Users are advised to restrict access to /dev/uinput to trusted users only. This is the default on most distributions, but some packages may alter udev rules to allow broader access. On Fedora, for example, packages like steam-device, antimicrox, and kdeconnectd can introduce such permissions.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
No references are available for this CVE.
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 8, 2026 | CVE Rejected | [email protected] |
| Jun 8, 2026 | CVE Modified | [email protected] |
| Jun 5, 2026 | CVE Modified | CVE |
| Jun 5, 2026 | New CVE Received | [email protected] |