CVE-2026-35093 identifies a high-severity vulnerability in libinput, allowing a local attacker to achieve unauthorized code execution and information disclosure. By placing a specially crafted Lua bytecode file in specific configuration directories, an attacker can bypass security restrictions and execute arbitrary code with the permissions of programs using libinput, such as a graphical compositor. This vulnerability is rated 8.8 HIGH, featuring a local attack vector with low complexity and requiring low privileges, with no user interaction. Successful exploitation could lead to significant impacts, including monitoring keyboard input and exfiltrating sensitive data. Currently, there is no evidence of active exploitation, nor are public exploit modules available, though it has received some community discussion and limited media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.30.3CPE matchmatch criteria | cpe:2.3:a:freedesktop:libinput:*:*:*:*:*:*:*:* | ||
>= 1.30.4, < 1.31.1CPE matchmatch criteria | cpe:2.3:a:freedesktop:libinput:*:*:*:*:*:*:*:* | ||
43CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:43:*:*:*:*:*:*:* | ||
44CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:44:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.