libinput Security Notification

Several vulnerabilities have been found in the libinput library:

  1. CVE-2026-35093: Sandbox escape in plugins. A flaw in the plugin loader allowed the loading of precompiled bytecode that does not pass checks at runtime, thereby not being restricted by the sandbox. This creates an opportunity for an attack that allows a malicious plugin to gain unrestricted access to the system, depending on the user's privileges.

  2. CVE-2026-35094: Use after free leading to leakage of sensitive information. A plugin that calls the Lua __gc() function leaves a dangling pointer in the device name, which can be logged. Depending on the value in the memory cell, this may lead to the disclosure of sensitive information.

The vulnerabilities affect all distributions with libinput version 1.30.0 and newer. However, the use of Lua plugins is only possible if the compositor loads them. Currently, this concerns GNOME 50’s mutter,, KWin (git), and Niri (git),.
wlroots, sway, and river are not vulnerable..

Fedora 43 and 44 distributions use the -Dautoload-plugins option, which causes the plugins to be loaded regardless of compositor support. Arch, OpenSuSE, Ubuntu, Debian, and NixOS do not have this option and/or use older versions of libinput.

Affected versions: libinput 1.31.0, 1.30.[0-2]
Fixed versions: libinput 1.31.1, 1.30.3

Source: linux.org.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster