CVE-2026-35094 identifies a low-severity dangling pointer vulnerability within libinput, allowing an attacker with local access to deploy a malicious Lua plugin in specific system directories. This flaw can lead to information disclosure by printing a dangling pointer to system logs after a garbage collection cleanup, potentially exposing sensitive data if the memory location is re-used. Exploitation requires Lua plugins to be enabled in libinput and loaded by the compositor. Rated with a CVSS score of 3.3 (Low), there is currently no evidence of active exploitation, public exploit code, or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:freedesktop:libinput:-:*:*:*:*:*:*:* | ||
43CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:43:*:*:*:*:*:*:* | ||
44CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:44:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.