CVE-2026-50292 Details
Description
In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properties leading to arbitrary root code execution
A vulnerability exists in libinput versions prior to 1.30.4 and 1.31.x prior to 1.31.3, where the 'libinput-device-group' udev helper outputs the 'phys' attribute without proper escaping. This flaw allows a malicious user to inject udev properties that could be exploited to execute arbitrary code with root privileges. The issue arises when a uinput or uhid device is created with a 'phys' value containing a newline, which udev misinterprets as a separate property, potentially leading to local privilege escalation.
Users can upgrade to libinput versions 1.31.3 or 1.30.4, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 4, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://gitlab.freedesktop.org/libinput/libinput/-/work_items/1296 | CISA-ADP | Vendor Advisory |
| https://gitlab.freedesktop.org/libinput/libinput/-/commit/76f0d8a7f57e2868882864b4611281f12f704b55 | [email protected] | Patch |
| https://gitlab.freedesktop.org/libinput/libinput/-/work_items/1296 | [email protected] | Vendor Advisory |
| https://www.openwall.com/lists/oss-security/2026/06/04/5 | [email protected] | Mailing ListPatchThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-93 | Improper Neutralization of CRLF Sequences ('CRLF Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| freedesktop libinput | < 1.30.4 >= 1.31.0, < 1.31.3 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | Initial Analysis | [email protected] |
| Jun 4, 2026 | CVE Modified | CISA-ADP |
| Jun 4, 2026 | New CVE Received | [email protected] |